
advisories
Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

Staged static taint analysis framework for GitHub Actions workflows. Detects code injection vulnerabilities using taint-tracking and an impact…

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and…

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit…

Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration…

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d

Public advisory landing page documenting CVE-2026-54520, a high-severity path traversal vulnerability in ai-agent-automation's workflow executor,…

Curated vulnerability writeups with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for real-world software…

Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with…

Software Component Verification Standard (SCVS)

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

CVE-2021-44228 server-side fix for minecraft servers.

Curated vulnerability writeup collection with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for…

Proof-of-Concept for CVE-2024-52005: ANSI escape sequence injection in Git. Demonstrates incorrect 'not_affected' VEX claims in hardened container…

ClusterImagePolicy demo for cve-2022-42889 text4shell