
agentic-workflow-injection
Reproducible vulnerable and fixed GitHub Actions fixtures for agentic workflow injection (CVE-2026-44246), with measured detector coverage and…

Reproducible vulnerable and fixed GitHub Actions fixtures for agentic workflow injection (CVE-2026-44246), with measured detector coverage and…

Reproduces CVE-2026-44246, a prompt injection vulnerability in nnU-Net's GitHub Actions triage agent, demonstrating how issue content is inlined into…

Security-research lab: reproduction of CVE-2025-10894 (PR-title injection in GitHub Actions) — snapshot of nrwl/nx

Technical breakdown of CVE-2026-3854, a GitHub RCE via header injection in git push, explaining the vulnerability, exploitation technique, and…

Curated list of backdoor learning papers, surveys, and toolboxes, organizing poisoning-based attacks and defenses in deep learning for researchers…

Specialized reasoning LLM for source-code vulnerability detection in C/C++ and Python, with dataset construction, SFT/DPO training, and…


Proof-of-concept exploit and technical analysis for CVE-2019-18426, covering open redirect, CSP bypass, persistent XSS, and file system read in…

Curated collection of cybersecurity resources including tools, articles, and repositories, structured with YAML frontmatter and automated discovery…


Resources related to GitHub Security Lab

Curated collection of technical write-ups detailing RCE vulnerabilities in GitHub Desktop, GitHub CLI, and Claude Code, with CVE references and…

Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520

OWASP Smart Contract Security (SCS) Project

Obsidian notes about CVE-2024-3094

Proof-of-concept exploit for CVE-2024-21532, a command injection vulnerability in the ggit npm package's fetchTags API, demonstrating unsafe exec()…

Research tool for enumerating WhatsApp user accounts via phone number probing, demonstrating large-scale enumeration vulnerabilities and their…

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2