
drupalgeddon2-cve-lab
Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

Docker lab demonstrating CVE-2026-12243 path traversal in NLTK before 3.10.0, contrasting vulnerable and patched behavior with a synthetic secret in…

A tool to manage vulnerable docker containers

Local Docker lab reproducing CVE-2026-39987, a pre-auth RCE in marimo's terminal WebSocket. Compares vulnerable and patched versions with least-harm…

Container escape on any docker container with healthcheck enabled via CVE-2026-31431

Docker lab to compare vulnerable and patched builds of MCPJam Inspector for CVE-2026-23744, demonstrating network binding differences and API…

Local Docker lab for comparing vulnerable and patched versions of WPvivid Backup & Migration (CVE-2026-1357) for educational verification and…

Make it possible to build a vulnerable webmin virtual environment as a container using docker

Docker-based vulnerable lab for CVE-2026-3288 NGINX Ingress configuration injection, with exploit scripts, detection monitoring, and remediation…

Educational lab simulating CVE-2025-3248 with a vulnerable Docker service and PoC exploit for hands-on security training and mitigation practice.

Dockerized vulnerable Telnet service for testing CVE-2026-24061, providing a controlled environment for vulnerability validation and security…

Automates CVE-2026-42945 exploitation in NGINX containers: verifies vulnerable targets, brute-forces heap offsets, executes commands, and opens an…

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability…

Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine,…

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Reproduces CVE-2026-21019 by manipulating node clock to force early Kubernetes CronJob execution; includes vulnerable YAML manifest and Python…

Exploit PoC and vulnerable admission webhook for CVE-2026-5556, demonstrating Kubernetes admission controller bypass via case-sensitive pod name…