
CVE-2024-3094-checker
Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

Technical analysis and Proof-of-Concept (PoC) for a critical Path Traversal vulnerability via Symlink manipulation in the Node.js 'tar' package…

POC of CVE-2021-42574 for solidity and solc compiler

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

Educational Python target range simulating CVE-2026-22807, an AI supply chain RCE via TOCTOU in model loading. Includes vulnerable library, PoC…

CVE-2025-47273 is a high-severity path traversal vulnerability in the setuptools library ,specifically version 78.1.0 .

Bash PoC for CVE-2024-32002 that exploits Git clone with malicious submodules and symlinks to execute arbitrary commands on Windows and macOS.

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

PoC for CVE-2025-62518 demonstrating tar archive smuggling via tokio-tar PAX header parsing, creating malicious payloads and a vulnerable extractor…

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.


Hook for the PoC for exploiting CVE-2024-32002

CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

PoC for CVE-2025-54416 tj-actions/branch-names command injection

CVE-2019-10172 PoC and Possible mitigations

Repository for CVE-2014-4936 POC code.