
melange
Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Offline and security-first tool for syncing and managing agent skills

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Proof-of-concept for CVE-2026-23001: demonstrates RCE through unsafe pickle deserialization in Hugging Face Transformers by crafting a malicious…

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

Signing-key abuse and update exploitation framework

Proof-of-concept exploit for CVE-2024-5082, a remote code execution vulnerability in Sonatype Nexus Repository Manager 2 via crafted Maven artifacts…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Educational lab replicating the XZ Utils backdoor (CVE-2024-3094) with a custom Ed448 key pair. Includes a patched liblzma, systemd service, and…

CVE-2025-65964 PoC - Malicious Git Hooks

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

CVE-2025-53547 one of poc code

This is the exploit of CVE-2018-6574: go get RCE

CocoaPods RCE Vulnerability CVE-2024-38366