
CVE-2025-9074-PoC
A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on…

A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on…

Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

Docker Container-to-Host Remote Code Execution POC via vllm-metal trust_remote_code=True

PHP poc, exploit for CVE-2025-9074

CVE-2021-21978 exp

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.

A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.

POE code for CVE-2017-1000112 adapted to both funtion on a specific VM and Escape a Docker

Some scripts to simulate an attack (used for CVE-2024-21626)

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492

3 linux kernel bugs chains to do secure comm app using side channel to establish key and establish covert channe;

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer