
CVE-2023-31606
Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Technical documentation and proof-of-concept for CVE-2019-7711, a format string vulnerability in Green Hills INTEGRITY RTOS Telnet server, enabling…

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

Analysis of DataDome's custom obfuscated VM and bytecode format, revealing string encryption, S-box ciphers, and browser fingerprinting signals for…

Stored XSS proof-of-concept for OpenKM notes section, demonstrating a javascript: bypass of sanitization rules, with CVSS 3.1 scoring and…

Research code for training adapters that make LLM agent backdoors survive benign fine-tuning, with trigger-rate scoring, SWE-bench evaluation, and…

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty…

Defense framework that mitigates malicious fine-tuning of LLMs using selective layer recovery and dynamic routing, with training, harmfulness…

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks

AES-CFB IV Generation Vulnerability in Reolink Desktop Application