
ship-safe
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Security training for the apps you actually ship. Open your browser and start hacking.

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Proof-of-concept exploit for CVE-2024-5082, a remote code execution vulnerability in Sonatype Nexus Repository Manager 2 via crafted Maven artifacts…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Proof-of-concept exploit for CVE-2024-21533, an argument injection vulnerability in the ggit npm package that allows arbitrary command execution via…

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

Sentinel demo: transitive snakeyaml CVE-2022-1471 via Spring Boot + exploitable code pattern

GNU IFUNC is the real culprit behind CVE-2024-3094

Proof-of-concept exploit for CVE-2026-44590, a command injection in Sherlock's GitHub Actions workflow enabling RCE and GITHUB_TOKEN exfiltration via…

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…