
security-labs-pocs
Proof of concept code for Datadog Security Labs referenced exploits.

Proof of concept code for Datadog Security Labs referenced exploits.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

CVE-2021-21978 exp

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

Proof-of-concept exploit for CVE-2026-41900, an unauthenticated remote code execution in OpenLearnX via container volume mount, enabling /tmp…

POC code for CVE-2024-29510 and demo VulnApp

* React2Shell-CVE-2025-55182

Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

* React2Shell-CVE-2025-55182

CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The…

Proof-of-concept exploit for CVE-2025-49131, a sandbox escape in FastGPT allowing arbitrary file read/write, import bypass, and remote code execution…