
Guardrails
Programmable guardrails for LLM chat apps: enforce input/output rails, block jailbreaks and prompt injections, detect hallucination, and mask…

Programmable guardrails for LLM chat apps: enforce input/output rails, block jailbreaks and prompt injections, detect hallucination, and mask…

PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched)

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Simulated 5G gNodeB NAS parser with stack buffer overflow PoC for CVE-2026-23002; a crafted NAS message triggers remote code execution.

Simulates CVE-2026-22019, a libcurl HTTP/2 CONNECT tunnel stream-isolation failure, demonstrating cross-stream data injection and response smuggling…

Python simulation of CVE-2026-22012, showing how a missing Final-Unit-Indication in Diameter Credit-Control allows unlimited quota and service bypass…

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Exploit for CVE-2026-66066 against Rails Active Storage/libvips: pre-auth arbitrary file read to recover SECRET_KEY_BASE and achieve RCE, with…

PoC exploit for CVE-2026-11114 demonstrating Node.js vm sandbox escape via Proxy to achieve remote code execution against a vulnerable HTTP /eval…

Educational Python PoC for a QUIC address-validation bypass that triggers handshake amplification, including vulnerable server simulation and attack…

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Educational analysis of CVE-2026-66066: Pre-auth RCE in Rails Active Storage libvips. Includes detection rules, IOCs, and mitigation guidance.

Reproducible lab for CVE-2026-66066: file-read-to-RCE exploit chain via Ruby on Rails Active Storage and libvips HDF5 matload. Includes Python…

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

Detailed security advisory and proof-of-concept for CVE-2026-67184, a NULL pointer dereference in TinyWeb leading to denial of service.


Proof-of-concept exploit for CVE-2019-5420, demonstrating remote code execution in Ruby on Rails via ActiveSupport deserialization. Generates signed…

A library for detecting known secrets across many web frameworks