
openclaw-technical-analysis
This technical research and review is for educational purposes on public code and constitutes Fair Dealing under the Copyright Act (Canada).

This technical research and review is for educational purposes on public code and constitutes Fair Dealing under the Copyright Act (Canada).

Technical analysis and proof-of-concept for Apache Struts 1 class parameter manipulation (CVE-2014-0114), demonstrating remote code execution on…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

Research code and experiments for defending tool-integrated LLM agents against adversarial attacks, extending Agent Security Bench with new defense…


Benchmark and defense code for persistent memory attacks on OpenClaw-style computer-use agents, with memory-zoning mitigation, attack scenarios, and…

Implements machine and deep learning methods for indoor UWB jammer localization, including hyperparameter optimization, classification, and…

Research code and dataset (WSD) for evaluating audio watermarking impact on anti-spoofing, using wav2vec2 XLS-R and knowledge-preserving learning.

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

Linux kernel 4.1.15 source code with a focus on CVE-2023-4128, intended for vulnerability analysis and educational study of kernel security.

Benchmark suite and code for detecting AI alignment failures, with 44 benchmarks across ten failure types and a zero-shot RLCD detector evaluated on…

An authenticated Remote Code Execution (RCE) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager…

Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520

PrISM: A Scalable Probabilistic RowHammer Mitigation (ISCA 2026). Ramulator2 source code and evaluation scripts.

Demonstrates CVE-2021-21300 arbitrary code execution via malicious Git hooks on case-insensitive filesystems, including exploit steps and defensive…

Microsoft Edge Elevation of Privilege Vulnerability