


A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...


Embed multiple secret messages in LLM chat token choices using arithmetic/Discop steganographic coders, with bit-exact decoding and steganalysis…

Proof of Concept of Libreoffice file exfiltration vulnerability in Big Blue Button

CVE-2025-24071 Proof Of Concept

CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit

FOGProject Authentication bypass CVE-2025-58443 Exploit


Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

CVE-2025-55182 & CVE-2025-66478 proof of concepts

A XXE payload generator



CVE-2019-14678: XML External Entity in SAS XML Mapper

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

POC of CVE-2026-51031 for arbitrary local file read