
CVE-2026-52617
Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.




Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

Advisory for pdf-image ⌯⌲ 10 000 weekly downloads

Advisory for textract ⌯⌲ 15 000 weekly downloads

Advisory for node-tesseract-ocr ⌯⌲ 50 000 weekly downloads


Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

CVE-2025-6384: Groovy Sandbox Bypass 2 in CrafterCMS

OS Command Injection Vulnerability via Plugin Execution in Figma Desktop Application

cve-2025-4615 poc & deep dive