
CVE-2017-1000117_wasawasa
Minimal test repository demonstrating Git's CVE-2017-1000117 recursive clone vulnerability for educational exploitation verification.

Minimal test repository demonstrating Git's CVE-2017-1000117 recursive clone vulnerability for educational exploitation verification.

Educational lab simulating npm supply chain attacks, CI/CD abuse, and install-time code execution via CVE-2026-45321. Hands-on defensive security…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

Curated resource hub for Log4j CVE-2021-44228, covering detection, mitigation, exploitation, and dependency management strategies for the critical…

Technical analysis and writeup of CVE-2024-3094, the XZ Utils backdoor. Explores the supply-chain attack, exploitation mechanics, and detection…

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

CVE-2024-24787 Proof of Concept

CVE-2018-17456漏洞复现(PoC+Exp)

Proof-of-concept exploit for CVE-2026-38945, demonstrating path traversal in RayVentory Scan Engine's Java detection to execute arbitrary binaries.

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

CVE-2018-11235(PoC && Exp)

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)