



Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

Proof of concept code for breaking out of docker via runC

PoC for CVE-2019-5736

A collection of manifests that will create pods with elevated privileges.

A container analysis and exploitation tool for pentesters and engineers.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

PoC and Detection for CVE-2024-21626

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Educational proof-of-concept for CVE-2025-31133, a runc container escape via maskedPaths race condition. Includes lab setup, exploit script, and…

Docker CVE-2022-37708

POCs and Tetragon Rules for CVE-2024-21626 and CVE-2025-31133

PoC for CVE-2024-21626: runc leaks an internal fd referencing the host CWD before pivot_root, enabling container escape by setting process.cwd to…

C-based PoC for CVE-2019-5736

CVE-2019-5736 POCs

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

getshell test