
CVE-2017-1000117
Proof-of-concept exploit for CVE-2017-1000117, a remote code execution vulnerability in git clients prior to v2.14.1, demonstrating recursive clone…

Proof-of-concept exploit for CVE-2017-1000117, a remote code execution vulnerability in git clients prior to v2.14.1, demonstrating recursive clone…

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

Python script to scan Git repos for interesting strings

Authenticated remote code execution exploit for Jenkins Git Client Plugin 2.8.2 via Jackson deserialization vulnerability (CVE-2019-10392).

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

Jenkins plugin providing Git APIs for automated repository operations including fetch, checkout, merge, and tag, with support for credential-based…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation on Windows systems for…

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation via crafted repository…

Proof-of-concept exploit for CVE-2024-32004, a Git remote code execution vulnerability, demonstrating exploitation via a malicious upload-pack filter.

PoC: identify silent security patches before CVE

Proof-of-concept exploit for CVE-2018-11235, a remote code execution vulnerability in Git submodules. Includes Dockerfile for reproducible testing…

Demonstrates exploitation of CVE-2018-11235, a Git submodule RCE vulnerability, with build script and analysis for educational purposes.

A tool to hunt for credentials in github wild AKA git*hunt

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…