
mcp-server-attestation
Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Nuclei template to detect CVE-2025-24016 unsafe deserialization RCE in Wazuh servers via a crafted JSON payload that triggers a NameError.

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

My experiments in weaponizing Nim (https://nim-lang.org/)

Proof-of-concept exploit for CVE-2023-49314 demonstrating code injection in Asana Desktop on macOS via Electron Fuses, with automated vulnerability…


CVE-2026-76060 PoC for a ZoneMinder vulnerability leading to RCE

Proof-of-concept for CVE-2025-60787, demonstrating remote code execution in MotionEye <= 0.43.1b4 via client-side validation bypass and command…

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

Details about the Blind RCE issue(SPX-GC) in SPX-GC

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Automatic SSTI detection tool with interactive interface

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

a guard that blocks catastrophic agent actions

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本