
opa
Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

Exploits CVE-2026-41567 Docker escape using trojanized xz/unpigz binaries to gain a root shell on the host from inside a container.

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.


PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix

Linux LPE - Reliable Jail/Container Escape

Add go CVE-2026-43284 / CVE-2026-43500 (dirtyfrag) local privilege escalation exploit

go CVE-2026-31431 (CopyFail) local privilege escalation exploit

PHP poc, exploit for CVE-2025-9074

Docker Container-to-Host Remote Code Execution POC via vllm-metal trust_remote_code=True

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

Proof-of-concept exploit for CVE-2025-9074 enabling Docker Desktop API escape via raw HTTP requests. Provides an emulated interactive shell inside a…