

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.