
secretlint
Pluggable linting tool to prevent committing credential.

Pluggable linting tool to prevent committing credential.

nodejsscan is a static security code scanner for Node.js applications.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

safely install npm packages by auditing them pre-install stage

Sequelize JSON Cast SQL Injection

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

Proof-of-concept exploit demo for CVE-2025-66478 using Node.js

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.





"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Proof-of-concept exploit for CVE-2021-21315, a command injection vulnerability in Node.js, demonstrating remote code execution.