
gtfocli
GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

Reproducible Docker-based demonstration of CVE-2018-1058 PostgreSQL privilege escalation via uncontrolled search path, with vulnerable and patched…

A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on…

Proof-of-concept exploit for CVE-2024-21626, a runc container escape vulnerability allowing host file system access via crafted working directory in…

Proof-of-concept exploit for CVE-2022-25365, a privilege escalation vulnerability in Docker Desktop for Windows via named pipe impersonation.

This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH…

Bash-based PoC exploit for CVE-2025-9074 targeting unauthenticated Docker Engine API to achieve container escape and remote code execution via…


PHP poc, exploit for CVE-2025-9074

WorldFirst (Public) Docker API Exploit - My security researches involving Docker and Openshift

C-based proof-of-concept exploit for CVE-2023-4911, a local privilege escalation vulnerability in glibc ld.so. Includes Docker build and run…

Proof-of-concept exploit for CVE-2025-32463, a privilege-escalation vulnerability in sudo's chroot feature. Includes Docker environment and exploit…

CVE-2025-9074: Docker Desktop LPE via Docker Engine API wo/ AuthN in posix sh

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Proof-of-concept exploit for CVE-2019-5736, a container escape vulnerability in runc, enabling host shell access via Docker container breakout.

Docker + CVE-2015-2925 = escaping from --volume

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Dockerized proof-of-concept for CVE-2021-4034 (PwnKit), a local privilege escalation in polkit's pkexec, demonstrating root access from an…