
kata-containers
Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w…

Validation of best practices in your Kubernetes clusters

📦 Make security testing of K8s, Docker, and Containerd easier.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

A collection of manifests that will create pods with elevated privileges.

Proof of concept code for Datadog Security Labs referenced exploits.

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Writeup of CVE-2017-1002101 with sample "exploit"/escape

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Proof of concept for CVE-2020-15257 in containerd.

Proof-of-concept for CVE-2024-21626, a runc container escape vulnerability. Includes verification scripts, two exploitation methods (cron reverse…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…