
gha-lab-733c168b88
Reproduces CVE-2026-44246, a prompt injection vulnerability in nnU-Net's GitHub Actions triage agent, demonstrating how issue content is inlined into…

Reproduces CVE-2026-44246, a prompt injection vulnerability in nnU-Net's GitHub Actions triage agent, demonstrating how issue content is inlined into…

Research code for poisoning attacks on the PGM-index, demonstrating how to craft adversarial data to degrade learned index performance.

Educational analysis and proof-of-concept code for CVE-2021-4034 (pkexec local privilege escalation), with detailed comments explaining the…

I Found a Zero-Day Vulnerability in langchain — Here’s How It Went

Analyzes CVE-2024-38998, a prototype pollution vulnerability in requirejs 2.3.6, demonstrating how malicious config inputs can lead to DoS, RCE, or…

Proof-of-concept reproducer for Apache Camel camel-atmosphere-websocket dispatch header injection (CVE-2026-71300), demonstrating how an injected…

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

How Enable Security handles security vulnerabilities

Clickbait. The CVE is AI slop.

This repository provides the official implementation of POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models.

Proof-of-concept code for beating Google's ZK proof of quantum cryptanalysis

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527

Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security…

This repository documents research into deserialization behavior within Next.js React Server Components (RSC) using the Flight protocol. It focuses…

Security advisory detailing a critical CVE in Copilot AI where RAG-based citation links are forged to a third-party domain, enabling source…