
vm2
Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Sandbox untrusted code with safe access to the host.

Isolate untrusted applications on Windows using Windows Sandbox technology. Spawns Firefox and other apps in separate containers, preserving host…

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Exploit PoC for CVE-2026-64561: KVM/x86 shadow MMU use-after-free allowing a guest to escape to host root. Includes technical write-up, affected…

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Track CVE patch status for a KVM/x86 guest-to-host escape: affected and fixed versions, upstream fix commits, and per-distribution patch status.

Tracks patch status for the KVM/arm64 guest-to-host escape CVE-2026-46316 across Linux distributions, including affected/fixed versions and upstream…