
GuardModel
GitHub Action that scans ML model files for malicious code and security vulnerabilities

GitHub Action that scans ML model files for malicious code and security vulnerabilities

Technical analysis and writeup of CVE-2024-3094, the XZ Utils backdoor. Explores the supply-chain attack, exploitation mechanics, and detection…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Source-built nginx 1.25.5 container with backported CVE-2026-42945 fix, OpenSSL bump, full provenance chain, and VEX attestation.

CRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs

IOC scanner for agentic AI coding tools — detects Mini Shai-Hulud, Gemini CLI RCE, Cursor CVE-2026-26268, and DPRK PromptMink.

Checker and fixer for all 13 vulnerabilities in the Next.js May 2026 security release (CVE-2026-23870)

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

CVE-2020-8809 and CVE-2020-8810

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Cargo exploit from CVE-2023-38497

Educational lab simulating npm supply chain attacks, CI/CD abuse, and install-time code execution via CVE-2026-45321. Hands-on defensive security…

Scan codebases and GCP projects for exposed API credentials

Deliberately vulnerable Node.js demo target for CVE-2020-7602, used to showcase automated dependency vulnerability detection and one-click PR-based…

Exploit for remote command execution in Golang go get command.

Read-only safety scanner for Claude Code projects. Catches CVE-2025-59536, statusLine injection, prompt injection, and more.

Proof-of-concept exploit for CVE-2024-21533, an argument injection vulnerability in the ggit npm package that allows arbitrary command execution via…

GIT vulnerability | Carriage Return and RCE on cloning