
CVE-2026-21852-PoC
Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Educational Python target range simulating CVE-2026-22807, an AI supply chain RCE via TOCTOU in model loading. Includes vulnerable library, PoC…

CVE-2026-31900 Vulnerable Lab - psf/black GitHub Action RCE

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Open source solutions for SOC2, GDPR, and ISO27001

CS50 Cybersecurity Final Project - Analysis of CVE-2024-3094

Local proof-of-concept for CVE-2026-71557 demonstrating path traversal in go-git filesystem reference storage, including exploit logic and…

Demonstrates how a malicious Python package executes arbitrary commands during pip install via setup.py, highlighting PyPI supply chain and…

Path traversal (Tar Slip) in Cornac via _extract_archive (CVE-2026-43637)

Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)

Issue with tough, versions prior to 0.20.0 (Multiple CVEs)

Demonstration script simulating a supply chain attack through GitHub releases, highlighting the risk of malicious code in release artifacts.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Plugin for integrating Trivy with Aqua Security platform to scan IaC, pipelines, and dependencies for vulnerabilities and misconfigurations.

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider


Advisory for pdf-image ⌯⌲ 10 000 weekly downloads