
security-labs-pocs
Proof of concept code for Datadog Security Labs referenced exploits.

Proof of concept code for Datadog Security Labs referenced exploits.

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Run iOS apps without actually installing them!

Proof-of-concept CVE exploit and lab scripts for sandbox/VM isolation, targeting authorized environments such as Docker and virtual machines for…

PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

DaemonSet для митигации уязвимости CVE-2026-64564 (SCTPhantom)

CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

Local privilege escalation PoC for a Linux kernel SCTP ASCONF DEL-IP use-after-free, demonstrating a root shell from an unprivileged local user on…

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape


Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

CVE-2026-31431 (copy.fail) — adapted for constrained Java execution environments via FFM syscall layer + javac annotation processor delivery

Fawkes is a golang Mythic C2 Agent exclusively written by AI.