
fuzzilli
A JavaScript Engine Fuzzer

A JavaScript Engine Fuzzer

A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques

Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

Proof-of-concept exploit and writeup for CVE-2022-44789, a heap buffer overflow in MuJS JavaScript interpreter, including vulnerable version and…

Proof-of-concept exploit and technical write-up for CVE-2026-73319, a same-host javascript: URI XSS in XenForo before 2.3.13, including reproduction…

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

Reproduction of a WebAssembly use-after-free vulnerability in Mozilla's JavaScript engine, demonstrating a deterministic race condition and providing…

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor…

Technical analysis of Adobe Acrobat JavaScript trust boundary flaw, documenting native handler mappings and privilege-gating logic for CVE-2026-34621.

Proof-of-concept exploit for a V8 JavaScript engine vulnerability (CVE-2025-6554) demonstrating a TDZ bypass that leaks 'The Hole' sentinel, enabling…

Proof-of-concept exploit for CVE-2025-6554, a V8 JavaScript engine vulnerability allowing unauthorized access to uninitialized 'Hole' values via…

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute…

An attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or privilege escalation.

Technical disclosure for CVE-2024-28784 — a stored XSS vulnerability in IBM QRadar SIEM 7.5.0 UpdatePackage 7. The issue affects the Rule Wizard…

Temporary proof-of-concept verification artifacts for CVE-2024-4367, a PDF.js arbitrary JavaScript execution vulnerability.

JavaScript-based exploit for Adobe Reader CVE-2014-0521 with proof-of-concept PDFs demonstrating file reading and data exfiltration via WebDAV.