
deptrust
CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

Educational lab replicating the XZ Utils backdoor (CVE-2024-3094) with a custom Ed448 key pair. Includes a patched liblzma, systemd service, and…

Curated collection of verified patches for the Shellshock (CVE-2014-6271) bash vulnerability, with upstream, Debian, and custom patches plus SHA256…

CVE-2024-24590 ClearML RCE&CMD POC

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Signing-key abuse and update exploitation framework

Offline and security-first tool for syncing and managing agent skills

Generate malicious files using recently published bidi-attack (CVE-2021-42574)

Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/

CVE-2025-53547 one of poc code

Script to handle CVE 2022-42889

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Demonstration exploit for CVE-2022-32223: DLL hijacking in Node.js on Windows via malicious providers.dll, targeting OpenSSL installations.

Shell script to check if your system has a vulnerable version of XZ Utils affected by CVE-2024-3094, enabling quick detection of the supply-chain…

Proof of concept for CVE-2024-24590

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…