
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Proof-of-concept CVE exploit and lab scripts for sandbox/VM isolation, targeting authorized environments such as Docker and virtual machines for…

PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

Docker Container Escape POC via mlx-metal importlib

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

An exploit primitive in linux kernel inspired by DirtyPipe


Customizable Linux Persistence Tool for Security Research and Detection Engineering.


Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Proof of concept code for Datadog Security Labs referenced exploits.

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

A collection of manifests that will create pods with elevated privileges.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)