


Patched Vue 2.7.16 template compiler with fixes for CVE‑2024‑6783 and CVE-2024-9506

Hook for the PoC for exploiting CVE-2024-32002

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

RCE in NPM VSCode Extension


CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

Agent-Isolated Credential Broker for AI Agents

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

Demo consumer for invokeai 5.0.1 (CVE-2024-10821; version named in CVE prose) — endorctl scan target

Demo consumer for ollama v0.5.0 (vulnerable range for CVE-2024-12886) — endorctl scan target

Sonatype Nexus 2 - Authorized RCE POC

In-depth analysis of cve-2026-26555