
CVE-2026-65320-fastcore
Documents CVE-2026-65320, a tar-slip path traversal in fastcore's untar_dir(), with a harmless proof-of-concept demonstrating arbitrary file write…

Documents CVE-2026-65320, a tar-slip path traversal in fastcore's untar_dir(), with a harmless proof-of-concept demonstrating arbitrary file write…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

Educational analysis and proof-of-concept exploit for CVE-2025-3248, a critical unauthenticated code injection vulnerability in Langflow, including…

This walkthrough documents the complete compromise of the HTB machine Connected.

A contextual security auditing system for research artifacts

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

Detailed analysis of CVE-2026-22038, a high-severity vulnerability in AutoGPT Stagehand blocks that logs API keys in plaintext, including root cause,…

Deep dive into a critical SQL injection in Python's Ormar ORM — reproduction, fix, and tests

Proof-of-concept exploit for CVE-2026-33154, demonstrating remote code execution via SSTI in Dynaconf's Jinja resolver, with analysis and mitigation…

Proof-of-concept demonstrating prototype pollution in deephas <=1.0.7 (CVE-2026-25047) leading to arbitrary code execution and denial of service,…

Proof-of-concept exploit for CVE-2026-26030, demonstrating remote code execution via unsafe filter expressions in Microsoft Semantic Kernel's…