
CVE-2026-28496
Docker lab reproducing the FOSSBilling pre-auth RCE chain (CVE-2026-27604 auth bypass + CVE-2026-28496 Twig SSTI) with a Python PoC and patched…

Docker lab reproducing the FOSSBilling pre-auth RCE chain (CVE-2026-27604 auth bypass + CVE-2026-28496 Twig SSTI) with a Python PoC and patched…

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

Simulates CVE-2026-23007 serverless cold-start memory remanence; demonstrates how persistent global state across Lambda invocations can leak secrets…

PoC for CVE-2026-22015: malicious event injects environment variables into serverless functions, overwriting secrets and enabling privilege…

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

OWASP Serverless Top 10

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions