
adm-zip_LPE-PoC
CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction

CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction

Python PoC for CVE-2026-101894: symlink-chain path traversal in @xhmikosr/decompress. Includes local Node lab, lockfile version scan, and mass…

Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…

0-day malware detection for binaries, source & scripts (that doesn't suck)

Deliberately vulnerable Docker lab reproducing CVE-2026-33634: LiteLLM gateway SSRF via api_base plus a trojanized dependency, with a multi-phase…

UnrealIRCd 3.2.8.1 backdoor exploit — reverse shell via AB; trigger, built from scratch in Python using raw sockets. No Metasploit.

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Proof-of-concept exploit for CVE-2026-44590, a command injection in Sherlock's GitHub Actions workflow enabling RCE and GITHUB_TOKEN exfiltration via…

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.