
vex-repo-spec
VEX Repository Specification

VEX Repository Specification

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

Proof-of-concept exploit for CVE-2024-55587 in libarchive, demonstrating unsafe extraction via malicious ZIP files.

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

CVE-2025-47273 — setuptools path traversal PoC

Minimal test repository demonstrating Git's CVE-2017-1000117 recursive clone vulnerability for educational exploitation verification.

OpenSSL toolkit providing TLS/SSL protocols and general-purpose cryptographic library with command-line tools for key generation, certificate…

A vulnerable Boa web server detector.

Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)

Fix open source package uses tough-cookie 2.5.0 - CVE-2023-26136,

patched-bash-4.3 for CVE-2014-6271

Java library for creating and extracting archives (ZIP, tar, JAR) with integrated security patch for a reported vulnerability, used as a dependency…

Java library for creating and extracting archives (ZIP, TAR, JAR) with support for various compression formats. Note: version 3.5 contains a fix for…

Security training for the apps you actually ship. Open your browser and start hacking.

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…