
badPods
A collection of manifests that will create pods with elevated privileges.

A collection of manifests that will create pods with elevated privileges.

A tool that shows detailed information about named pipes in Windows

A structured explanation of CVE-2026-31431 (Copy Fail), connecting the three kernel changes that introduced the vulnerability and enabled its…

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break…

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

Educational proof-of-concept for CVE-2025-31133, a runc container escape via maskedPaths race condition. Includes lab setup, exploit script, and…

PHP poc, exploit for CVE-2025-9074

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Docker Container Escape POC via mlx-metal importlib

Docker CVE-2022-37708

Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…


Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213