
TrojanSourceFinder
🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)


Public OCI-Image (docker image) Security Checker

XZ Backdoor Extract(Test on Ubuntu 23.10)

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

Proof of Concept for CVE-2020-10759 (fwupd signature validation bypass)

Educational lab replicating the XZ Utils backdoor (CVE-2024-3094) with a custom Ed448 key pair. Includes a patched liblzma, systemd service, and…

Demo consumer for ollama v0.5.0 (vulnerable range for CVE-2024-12886) — endorctl scan target

Demo consumer for invokeai 5.0.1 (CVE-2024-10821; version named in CVE prose) — endorctl scan target

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Local proof-of-concept for CVE-2026-71557 demonstrating path traversal in go-git filesystem reference storage, including exploit logic and…

Detailed analysis of CVE-2022-21668, a critical RCE vulnerability in Pipenv's requirements.txt parsing, including bug code, exploit mechanics, and…