
PentestGPT
Automated Penetration Testing Agentic Framework Powered by Large Language Models

Automated Penetration Testing Agentic Framework Powered by Large Language Models

Advisories, proof of concept files and exploits that have been made public by @pedrib.

Cisco ASA Software and ASDM Security Research

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

adaptive agents for dynamic web penetration testing

CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata

CVE-2021-44228 Log4Shell — Penetration Test Writeup

MAL-003: Groovy Security Bypass and Stored XSS in Apache OfBiz

Proof-of-concept research repository for CVE-2026-42978, containing analysis and exploit code for the referenced vulnerability.

Proof-of-concept exploit code for CVE-2026-20805, demonstrating the vulnerability for security research and validation.

Modified proof-of-concept exploit for CVE-2026-23980, providing a working implementation for vulnerability reproduction and security testing.

Write-up on the CVE-2019-9745 vulnerability.

MAL-007: XML External Entity via Local Registry Entries in WSO2 ESB

MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server

PoC — path traversal via malicious device sync in the Supernote Obsidian plugin (GHSA-3gx3-r874-5pp4, CVE-2026-86999, CVSS 5.6).