
kube-linter
KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break…

Reproduction of CVE-2017-5123 kernel vulnerability allowing local privilege escalation via waitid syscall memory write, demonstrated with Docker…

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

Proof-of-concept exploit for CVE-2019-5736, appending a payload to the host runc binary via Docker container escape.

Docker + CVE-2015-2925 = escaping from --volume

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Golang rewrite of the Copy Fail (CVE-2026-31431) local privilege escalation exploit, corrupting page cache to gain root on Linux systems.

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…

Modified version of CVE-2019-5736-PoC by Frichetten

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

A container analysis and exploitation tool for pentesters and engineers.

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark