
react2shell-audit
A lightweight, recursive Bash script to detect Next.js and React Server DOM versions vulnerable to CVE-2025-55182 (React2Shell) in local projects.

A lightweight, recursive Bash script to detect Next.js and React Server DOM versions vulnerable to CVE-2025-55182 (React2Shell) in local projects.

PoC for CVE-2025-62518 demonstrating tar archive smuggling via tokio-tar PAX header parsing, creating malicious payloads and a vulnerable extractor…

Proof-of-concept exploit for CVE-2024-21533, an argument injection vulnerability in the ggit npm package that allows arbitrary command execution via…

Reproduction of CVE-2020-36518 in Spring Boot 2.5.10

Proof-of-concept and analysis tools for CVE-2024-3094, the XZ Utils backdoor vulnerability, including detection and exploitation scripts.

Analyzes and demonstrates the webpack CVE-2024-43788 vulnerability, providing detection and exploitation insights for security researchers.

Patch for zlib addressing CVE-2018-25032 in AOSP10 r33, providing a fix for the identified vulnerability.

PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

Minimal reproduction of CVE-2022-46175 demonstrating a JSON5 prototype pollution vulnerability in Quasar webpack projects for security education and…

Sample project to test using Microsoft.CodeDom.Providers.DotNetCompilerPlatform 2.0.1 causing CVE-2017-0248

Signing-key abuse and update exploitation framework

Backdooring Claude Code via hooks in settings.json. Authorized use only!

Proof-of-concept code for Android APEX key reuse vulnerability

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

Collect VEX documents and update VEX Hub

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Repository for CVE-2014-4936 POC code.

Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/