
CVE-2026-33626-Lab
Docker Compose lab reproducing CVE-2026-33626 SSRF in LMDeploy's vision-language image loader. Compares vulnerable (0.12.0) and patched (0.12.3)…

Docker Compose lab reproducing CVE-2026-33626 SSRF in LMDeploy's vision-language image loader. Compares vulnerable (0.12.0) and patched (0.12.3)…

Benchmark for evaluating safety risks of computer-using agents, with 104 realistic misuse scenarios across seven malicious categories, supporting…

Technical analysis of the LangChain serialization injection vulnerability CVE-2025-68664.

Open standard for documenting security-relevant metadata of AI models, including training data provenance, PII risk, known vulnerabilities, and…

A technical case study and timeline dataset documenting Google Gemini 2.5 Pro's safety alignment policies, guardrails, and refusal behavior evolution…

Reproducible AI-assisted vulnerability rediscovery of CVE-2026-42945 in nginx, including technical analysis, PoC trigger, and patch validation for…

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

This technical research and review is for educational purposes on public code and constitutes Fair Dealing under the Copyright Act (Canada).

Code repository for CS5446 project exploring defenses against jailbreak attacks on large-language models it includes datasets, notebooks,…

Artefacts for blog post on finding CVE-2025-37899 with o3

Automated threat hunting pipeline that ingests Azure logs, uses LLM reasoning to detect suspicious activity, assess risk, and generate remediation…

Educational Python target range simulating CVE-2026-22807, an AI supply chain RCE via TOCTOU in model loading. Includes vulnerable library, PoC…

CAWODOG is a proof-of-concept project demonstrating how to protect Python-based AI models deployed on offline industrial machines. Across three…

Exploit for Langflow AI Remote Code Execution (Unauthenticated)

Demonstrates AI agent-driven CVE remediation with cryptographic provenance tracking, showcasing detection, analysis, human approval, and verification…

AI powered security analysis extension for Mobile Security Framework MobSF

My manifesto, and stories, images, and phun stuff