
CVE-2025-61765_PoC
Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break…

Golang rewrite of the Copy Fail (CVE-2026-31431) local privilege escalation exploit, corrupting page cache to gain root on Linux systems.

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w…

Validation of best practices in your Kubernetes clusters

📦 Make security testing of K8s, Docker, and Containerd easier.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

A collection of manifests that will create pods with elevated privileges.

Proof of concept code for Datadog Security Labs referenced exploits.

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Writeup of CVE-2017-1002101 with sample "exploit"/escape

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Proof of concept for CVE-2020-15257 in containerd.