
incus-os
Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Official QEMU mirror. Please see https://www.qemu.org/contribute/ for how to submit changes to QEMU. Pull Requests are disabled. Please only use…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

Secure code execution

Rex is a safe and usable kernel extension framework that allows loading and executing Rust kernel extension programs in the place of eBPF.

Main UserLAnd Repository

Sandbox untrusted code with safe access to the host.

Exploit PoC for CVE-2026-64561: KVM/x86 shadow MMU use-after-free allowing a guest to escape to host root. Includes technical write-up, affected…

Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape

Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

A Linux framework to enable userspace-defined "Virtual" PCIe card shims to enable in-host PCIe card driver development.

Kali Linux VM images build script