
CDK
📦 Make security testing of K8s, Docker, and Containerd easier.

📦 Make security testing of K8s, Docker, and Containerd easier.

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

A container analysis and exploitation tool for pentesters and engineers.

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492

CVE-2024-0132 – Fully Weaponized NVIDIA Container Toolkit Exploit

Educational proof-of-concept for CVE-2025-31133, a runc container escape via maskedPaths race condition. Includes lab setup, exploit script, and…

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

Docker Container Escape POC via mlx-metal importlib

Container Runtime Meetup #5 のLT用のデモ

CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit

Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…

PoC for CVE-2024-21626: runc leaks an internal fd referencing the host CWD before pivot_root, enabling container escape by setting process.cwd to…