
otto-support
An implementation of a vulnerable MCP server using mcp-go
api-securityauthentication-authorizationctf+5

An implementation of a vulnerable MCP server using mcp-go

Proof-of-concept exploit for CVE-2026-49757 demonstrating OAuth2/OIDC account takeover via email-based user matching in AshAuthentication, with…

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

The full repo of all the labs available as part of the benchmark