
k0otkit
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

PoC and Detection for CVE-2024-21626

Exploit for CVE-2025-1974 targeting ingress-nginx controllers in Kubernetes, enabling container escape via crafted shared object injection and shell…

CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

CVE-2022-0185 POC and Docker and Analysis write up

Exploit for CVE-2021-25741 Kubernetes vulnerability allowing host filesystem mount into pods via race condition, with deployment scripts and…

CVE-2021-21978 exp

非常简单的CVE-2023-0386's exp and analysis.Use c and sh.

Demo-ing CVE-2017-1000253 in a container

Proof-of-concept exploit for CVE-2022-39253 demonstrating Docker container escape via malicious Git repository build, enabling host file system read…

Proof-of-concept exploit for CVE-2025-9074 demonstrating container-to-host file write via exposed Docker Engine API on Windows. For authorized…

Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)

Proof-of-concept for CVE-2024-21626, a runc container escape vulnerability. Includes verification scripts, two exploitation methods (cron reverse…

Proof-of-concept exploit for CVE-2024-21626 runc container breakout via leaked file descriptors and process.cwd manipulation, enabling host…

Proof-of-concept exploit for Kata Containers container escape (CVE-2020-2023) using mknod to modify guest filesystem and overwrite system binaries…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

CVE-2022-0492-Container-Escape
