Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
141 commits
Select commit Hold shift + click to select a range
e5e9f75
Add PoC validation helper and regression tests
Copilot Jul 13, 2026
ac12e3e
Validate PoC collection repeatedly
Copilot Jul 13, 2026
b178330
Merge pull request #1 from 5hy7xz92nd-oss/copilot/learn-upgrade-save-…
5hy7xz92nd-oss Jul 13, 2026
27372a8
Merge branch 'bikini:main' into main
5hy7xz92nd-oss Jul 22, 2026
e8e8f42
Update README.md
5hy7xz92nd-oss Jul 27, 2026
b57737c
Apply remaining changes
Copilot Jul 27, 2026
b901278
Merge pull request #2 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Jul 28, 2026
4af40b6
Potential fix for pull request finding
5hy7xz92nd-oss Aug 2, 2026
2224f55
Apply remaining changes
Copilot Aug 3, 2026
e25dc96
Merge pull request #3 from 5hy7xz92nd-oss/copilot/duplicate-icon-reso…
5hy7xz92nd-oss Aug 3, 2026
e5a1cfc
Merge pull request #4 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 3, 2026
7c7309b
Merge pull request #5 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 3, 2026
e44a3c7
Merge pull request #6 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 3, 2026
da3b2d7
Merge pull request #7 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 3, 2026
ce90d12
Merge pull request #8 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 3, 2026
3a61b7f
Merge pull request #9 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 3, 2026
9fe6bc4
Merge pull request #10 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 3, 2026
fb94734
Merge pull request #11 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 3, 2026
01e7f9e
Apply remaining changes
Copilot Aug 4, 2026
9c8d9fd
Apply remaining changes
Copilot Aug 4, 2026
67de903
Apply remaining changes
Copilot Aug 4, 2026
639c798
Merge pull request #12 from 5hy7xz92nd-oss/copilot/we-are-one-hologra…
5hy7xz92nd-oss Aug 4, 2026
83d3dda
Initial plan
Copilot Aug 4, 2026
1e7c47b
Initial plan
Copilot Aug 4, 2026
513ea9c
Merge pull request #16 from 5hy7xz92nd-oss/copilot/wip-address-feedba…
5hy7xz92nd-oss Aug 4, 2026
86a3123
Merge pull request #17 from 5hy7xz92nd-oss/copilot/1k-repo-decentrali…
5hy7xz92nd-oss Aug 4, 2026
d895a36
Merge pull request #18 from 5hy7xz92nd-oss/copilot/awesome-ai-driven-…
5hy7xz92nd-oss Aug 5, 2026
43cbbd5
Merge pull request #19 from 5hy7xz92nd-oss/copilot/awesome-ai-drivend…
5hy7xz92nd-oss Aug 5, 2026
72338e1
Merge pull request #20 from 5hy7xz92nd-oss/copilot/wip-address-feedba…
5hy7xz92nd-oss Aug 5, 2026
7d784db
Merge pull request #21 from 5hy7xz92nd-oss/copilot/manusweareone10bil…
5hy7xz92nd-oss Aug 5, 2026
5add847
Merge pull request #22 from 5hy7xz92nd-oss/copilot/we-are-one-hologra…
5hy7xz92nd-oss Aug 5, 2026
9c30d77
Merge pull request #23 from 5hy7xz92nd-oss/copilot/duplicate-icon-res…
5hy7xz92nd-oss Aug 5, 2026
b189994
Merge pull request #24 from 5hy7xz92nd-oss/copilot/sync-rabbit-data
5hy7xz92nd-oss Aug 5, 2026
159e894
Merge pull request #25 from 5hy7xz92nd-oss/copilot/weareone10billion
5hy7xz92nd-oss Aug 5, 2026
e8aa06f
Merge pull request #26 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 5, 2026
97fd667
Changes before error encountered
Copilot Aug 5, 2026
2ec10ad
Initial plan
Copilot Aug 5, 2026
31278f2
Merge pull request #27 from 5hy7xz92nd-oss/copilot/fix-249378113-1299…
5hy7xz92nd-oss Aug 5, 2026
f902eaa
Merge pull request #28 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 5, 2026
fa0c932
Merge pull request #29 from 5hy7xz92nd-oss/copilot/we-are-one-hologra…
5hy7xz92nd-oss Aug 5, 2026
1896c65
Merge pull request #30 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 5, 2026
2ef4ba6
Merge pull request #31 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 5, 2026
730ff15
Merge pull request #32 from 5hy7xz92nd-oss/copilot/auto-sync-updates
5hy7xz92nd-oss Aug 5, 2026
e192ca8
Merge pull request #33 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
1dc147f
Merge pull request #34 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
84dd016
Merge pull request #35 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
ef4d70c
Merge pull request #36 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
7979967
Merge pull request #37 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
c1a2318
Merge pull request #38 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
ae6dc47
Merge pull request #39 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
09de1fd
Merge pull request #40 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
c1ea5c6
Merge pull request #41 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
898804a
Merge pull request #42 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
5cda9d5
Merge pull request #43 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
0d5b67f
Merge pull request #44 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
dd0ab6e
Merge pull request #45 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
506bd49
Merge pull request #46 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
c0bbd41
Merge pull request #47 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
58fee01
Merge pull request #48 from 5hy7xz92nd-oss/copilot/auto-sync-updates
5hy7xz92nd-oss Aug 5, 2026
7b492fb
Merge pull request #49 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 5, 2026
af1db8b
Merge pull request #50 from 5hy7xz92nd-oss/copilot/weareone10billion
5hy7xz92nd-oss Aug 5, 2026
b632dd8
Merge pull request #51 from 5hy7xz92nd-oss/copilot/awesome-ai-drivend…
5hy7xz92nd-oss Aug 5, 2026
31a3571
Merge pull request #52 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 5, 2026
6dc17d1
Merge pull request #53 from 5hy7xz92nd-oss/copilot/sync-rabbit-data
5hy7xz92nd-oss Aug 5, 2026
16c0c93
Merge pull request #54 from 5hy7xz92nd-oss/copilot/create-pull-request
5hy7xz92nd-oss Aug 5, 2026
7a215dd
Merge pull request #55 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 5, 2026
4a51246
Merge pull request #56 from 5hy7xz92nd-oss/copilot/1k-repo-decentrali…
5hy7xz92nd-oss Aug 5, 2026
48bb2e0
Merge pull request #57 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 5, 2026
e77717d
Merge pull request #60 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
62b38cc
Merge pull request #61 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
22057b4
Merge pull request #62 from 5hy7xz92nd-oss/copilot/awesome-ai-driven-…
5hy7xz92nd-oss Aug 5, 2026
77425c1
Merge pull request #63 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
54c138d
Merge pull request #64 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 5, 2026
11efd5f
Merge pull request #65 from 5hy7xz92nd-oss/copilot/wip-address-feedba…
5hy7xz92nd-oss Aug 5, 2026
6cec1a2
Merge pull request #66 from 5hy7xz92nd-oss/copilot/auto-sync-updates
5hy7xz92nd-oss Aug 5, 2026
86ae7b1
Merge pull request #67 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 5, 2026
35f372f
Merge pull request #68 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
bc5b330
Merge pull request #70 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
c58f934
Merge pull request #71 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 5, 2026
50a2b34
Merge pull request #72 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 6, 2026
131011c
Merge pull request #73 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 6, 2026
99ad1d0
Merge pull request #74 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 6, 2026
11399b8
Merge pull request #75 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 6, 2026
66ee02b
Merge pull request #76 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 6, 2026
6bdc69c
Merge pull request #77 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 6, 2026
5842abf
Merge pull request #78 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 6, 2026
435dc1d
Merge pull request #79 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 8, 2026
1dc6c05
Merge pull request #80 from 5hy7xz92nd-oss/copilot/awesome-ai-drivend…
5hy7xz92nd-oss Aug 8, 2026
89f1537
Merge pull request #81 from 5hy7xz92nd-oss/copilot/1k-repo-decentrali…
5hy7xz92nd-oss Aug 8, 2026
527dcc9
Merge pull request #82 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 8, 2026
90d84af
Merge pull request #83 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
6377d68
Merge pull request #85 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
5e6a313
Merge pull request #86 from 5hy7xz92nd-oss/copilot/auto-sync-updates
5hy7xz92nd-oss Aug 9, 2026
034376c
Merge pull request #87 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
37c97b8
Merge pull request #88 from 5hy7xz92nd-oss/copilot/awesome-ai-driven-…
5hy7xz92nd-oss Aug 9, 2026
72670a6
Merge pull request #89 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
3d2e4fe
Merge pull request #90 from 5hy7xz92nd-oss/copilot/auto-sync-updates
5hy7xz92nd-oss Aug 9, 2026
983c6de
Merge pull request #91 from 5hy7xz92nd-oss/copilot/learn-upgrade-save…
5hy7xz92nd-oss Aug 9, 2026
60ed059
Start validation and CI upgrade work
Copilot Aug 9, 2026
dd394b0
Expand PoC validation, tests, CI, and ignore bytecode
Copilot Aug 9, 2026
5178e3c
Use Counter for catalog duplicate detection
Copilot Aug 9, 2026
f5d4a50
Limit CI workflow GITHUB_TOKEN permissions
Copilot Aug 9, 2026
e20fa69
Fix root-relative excludes and harden validation gates
Copilot Aug 9, 2026
72ce524
Apply remaining changes
Copilot Aug 9, 2026
784d598
Merge pull request #93 from 5hy7xz92nd-oss/copilot/validate-pocs-fix
5hy7xz92nd-oss Aug 9, 2026
122975b
Potential fix for pull request finding
5hy7xz92nd-oss Aug 9, 2026
27ad62f
Resolve merge conflicts with main
Copilot Aug 9, 2026
8520a00
Merge pull request #92 from 5hy7xz92nd-oss/copilot/update-and-upgrade…
5hy7xz92nd-oss Aug 9, 2026
ec42eba
Update print statement from 'Hello' to 'Goodbye'
5hy7xz92nd-oss Aug 9, 2026
7d1a2c0
Merge pull request #94 from 5hy7xz92nd-oss/patch-1
5hy7xz92nd-oss Aug 9, 2026
0d67212
Merge pull request #95 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
70823c5
Merge pull request #96 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
7439329
Merge pull request #97 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
c45bdcb
Merge pull request #99 from 5hy7xz92nd-oss/copilot/awesome-ai-driven-…
5hy7xz92nd-oss Aug 9, 2026
94c3160
Merge pull request #100 from 5hy7xz92nd-oss/patch-1
5hy7xz92nd-oss Aug 9, 2026
e4cc471
Merge pull request #101 from 5hy7xz92nd-oss/patch-1
5hy7xz92nd-oss Aug 9, 2026
1072cc8
Merge pull request #102 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
eb9a2c1
Merge pull request #104 from 5hy7xz92nd-oss/copilot/awesome-ai-driven…
5hy7xz92nd-oss Aug 9, 2026
78f7d89
Merge pull request #106 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 9, 2026
eefdb23
Merge pull request #107 from 5hy7xz92nd-oss/copilot/1k-repo-decentral…
5hy7xz92nd-oss Aug 9, 2026
ffc2633
Initial plan
Copilot Aug 9, 2026
da271fa
Initial plan
Copilot Aug 9, 2026
ffab5e1
Exclude package.json from generic JSON validation
Copilot Aug 9, 2026
f6e406a
Avoid double-validating package.json in JSON pass
Copilot Aug 9, 2026
f454a93
Merge pull request #109 from 5hy7xz92nd-oss/copilot/fix-code-comments…
5hy7xz92nd-oss Aug 9, 2026
de47a7a
Merge pull request #108 from 5hy7xz92nd-oss/copilot/fix-review-commen…
5hy7xz92nd-oss Aug 9, 2026
76b264b
Merge pull request #110 from 5hy7xz92nd-oss/copilot/auto-sync-updates
5hy7xz92nd-oss Aug 9, 2026
a348292
Merge pull request #111 from 5hy7xz92nd-oss/main
5hy7xz92nd-oss Aug 9, 2026
92ac4c5
Merge pull request #112 from 5hy7xz92nd-oss/copilot/auto-sync-updates
5hy7xz92nd-oss Aug 9, 2026
e2dc40a
Merge pull request #115 from 5hy7xz92nd-oss/patch-1
5hy7xz92nd-oss Aug 10, 2026
da153cd
Merge pull request #118 from 5hy7xz92nd-oss/copilot/add-feature-request
5hy7xz92nd-oss Aug 10, 2026
a1c7d2a
Improve README architecture docs and add contributing/changelog
Copilot Aug 11, 2026
31302e9
Merge pull request #124 from 5hy7xz92nd-oss/copilot/include-all-ingre…
5hy7xz92nd-oss Aug 11, 2026
dc0e7b0
Extend repository validator coverage
Copilot Aug 11, 2026
7384744
Address validator review feedback
Copilot Aug 11, 2026
36bee5d
Merge pull request #125 from 5hy7xz92nd-oss/copilot/integrate-impleme…
5hy7xz92nd-oss Aug 11, 2026
bec086a
Merge pull request #58 from 5hy7xz92nd-oss/copilot/task-249378113-129…
5hy7xz92nd-oss Aug 11, 2026
c614fe9
Merge pull request #59 from 5hy7xz92nd-oss/copilot/we-are-one-hologra…
5hy7xz92nd-oss Aug 12, 2026
7d46c92
Update README.md
5hy7xz92nd-oss Aug 14, 2026
fd3acf4
Potential fix for pull request finding
5hy7xz92nd-oss Aug 14, 2026
222c359
Potential fix for pull request finding
5hy7xz92nd-oss Aug 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1,487 changes: 1,487 additions & 0 deletions .github/instructions/*.instructions.md

Large diffs are not rendered by default.

33 changes: 33 additions & 0 deletions .github/workflows/validate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
name: Validate

on:
push:
pull_request:
workflow_dispatch:

permissions:
contents: read

jobs:
validate:
name: Unit tests and PoC validation
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"

- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: "22"

- name: Run unit tests
run: python -m unittest discover -s tests -v

- name: Validate repository integrations
run: python validate_pocs.py
13 changes: 13 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,18 @@
.DS_Store
Thumbs.db
__pycache__/
*.py[cod]
*$py.class
.pytest_cache/
.mypy_cache/
.ruff_cache/
.venv/
venv/
node_modules/
target/
*.egg-info/
.coverage
htmlcov/
libssh2-publickey-list-calc-poc/build/
libssh2-publickey-list-calc-poc/x86_calc_payload_reached.txt
libssh2-publickey-list-calc-poc/x64_calc_payload_reached.txt
15 changes: 15 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Changelog

All notable repository-level documentation/validation changes are tracked here.

## Unreleased

### Added

- Added `docs/architecture.md` documenting repository components, validation pipeline, and a code-derived dependency graph.
- Added `CONTRIBUTING.md` with contribution workflow and validation requirements.

### Changed

- Expanded root `README.md` with architecture overview, repository-level dependency documentation, and links to key docs/changelog.
- Added a repository-level component dependency graph to `README.md`.
53 changes: 53 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
# Contributing

Thanks for helping improve Exploitarium.

## Repository contribution scope

This repository primarily accepts:

- New self-contained PoC/research folders
- Updates to existing PoC folders
- Repository-level validation and documentation improvements

## Required structure for new top-level entries

For a new top-level PoC/research folder:

1. Add a folder at repository root (non-hidden).
2. Include a `README.md` in that folder.
3. Add/update any supporting files (scripts, manifests, evidence, payloads).
4. Add the folder to the root catalog table in `/README.md`.

## Validation requirements

Before opening a PR, run:

```bash
python -m unittest discover -s tests -v
python validate_pocs.py
```

`validate_pocs.py` checks:

- Python syntax for tracked `*.py`
- `package.json` and generic `*.json` parse validity
- `Cargo.toml` shape for package metadata
- `requirements*.txt` has meaningful dependency entries
- JavaScript syntax via `node --check`
- Per-entry `README.md` presence
- Root catalog consistency in `/README.md`

## Dependency notes

- Python 3.11+ is required for repository validation.
- Node.js is required for JavaScript syntax checks.
- PoC-specific dependencies should be documented in each entry's `README.md`.

## Pull request checklist

- [ ] Entry folder(s) include `README.md`
- [ ] Root `README.md` catalog updated (if top-level entries changed)
- [ ] `python -m unittest discover -s tests -v` passes
- [ ] `python validate_pocs.py` passes
- [ ] Documentation updated where applicable (`README.md`, `docs/architecture.md`, `CHANGELOG.md`)
72 changes: 67 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Statement
# 🕴️Statement

This repo was incomplete when published.
This repo was incomplete when published.

In regard to AI usage, my fuzzing workflow was automated by AI with a strict workflow. I used GPT-5.3 for ALL the fuzzing, as barely any "thought" is necessary when provided with an efficient workflow. Contrary to the growing narrative that I'm just some random child burning tokens, I DO actually have a degree in the subject and have published multiple papers on fuzzing methodology. I spent years researching and developing new tools and ideas for how to fuzz. You do NOT need a SOTA model to help you identify these issues, I promise! While being able to afford a better model is helpful, my data seems to show that it is only marginal when paired with decent human oversight and a good workflow. None of the actual PoCs themselves were vibe-coded; I did, in fact, hand-type them. I did use AI assistance for RustDesk, however, as I'm not as familiar with the language. The README files are very clearly entirely AI, however, as AI can format a pretty mean Markdown file. I reviewed them to make sure they were accurate.

Expand All @@ -13,15 +13,57 @@ I've also noticed a surprising amount of "security researchers" aren't able to a

If you wish to collaborate/discuss with me, contact me on telegram @ashdfrkl

Sharing this repo keeps me motivated to continue dropping my findings for you all.

Sharing this repo keeps me motivated to continue dropping my findings for you all.

# Exploitarium

A consolidated archive of my public proof-of-concept and vulnerability research writeups.

Most folders contain one of my former standalone PoC repos, preserved with its original README and tracked files. New research entries are added directly here as self-contained folders.

## Project architecture

At repository level, architecture is intentionally simple:

- **PoC directories** (top-level `*-poc` folders and similar research folders) contain exploit writeups, scripts, payloads, and per-entry `README.md` files.
- **`validate_pocs.py`** is the integration gate that discovers tracked artifacts and validates syntax/manifests/catalog integrity.
- **`tests/test_validate_pocs.py`** unit-tests the validator behavior and discovery rules.
- **`.github/workflows/validate.yml`** runs unit tests plus `validate_pocs.py` on every push/PR.
- **Root docs** (`README.md`, `cves.md`, `docs/architecture.md`, `CONTRIBUTING.md`, `CHANGELOG.md`) document usage, architecture, and repository history.

### Dependency graph (from current code)

```mermaid
flowchart TD
A[.github/workflows/validate.yml] --> B[python -m unittest discover -s tests -v]
A --> C[python validate_pocs.py]
B --> D[tests/test_validate_pocs.py]
D --> C
C --> E[README.md catalog rows]
C --> F[PoC directories]
F --> G[README.md per PoC]
F --> H[*.py, *.js, *.mjs, *.cjs, *.sh, package.json, Cargo.toml, requirements*.txt, *.json, SHA256SUMS.txt]
```

## Dependencies

### Repository validation dependencies

- **Python 3.11+** (CI uses 3.12): required for `validate_pocs.py` and unit tests (`tomllib` is used from the standard library).
- **Node.js** (`node --check`): required by `validate_pocs.py` to syntax-check JavaScript PoC files.
- **No third-party Python package is required** for repository-level validation.

### PoC-specific dependencies

Individual PoC folders may require their own stacks (for example Rust/Cargo, C/C++ toolchains, Java/JDK, browser runtimes, Docker/QEMU, or Python packages listed in per-entry `requirements*.txt`). Treat each entry README as the source of truth for runtime/build prerequisites.

## Documentation

- [Architecture details](docs/architecture.md)
- [Contributing guide](CONTRIBUTING.md)
- [Changelog](CHANGELOG.md)
- [CVE list from this repository](cves.md)

## Contents

| Folder | Source | Tracked entries |
Expand Down Expand Up @@ -66,6 +108,26 @@ Most folders contain one of my former standalone PoC repos, preserved with its o
| `systeminformer-phsvc-trusted-host-lpe-poc` | direct entry, June 24, 2026 | 3 |
| `vlc-vp9-reschange-crash-poc` | `fae72b82f24d03cf2fb9cb55fbb2e7774f684ff3` | 3 |

## Validation

Repository integrity checks live in `validate_pocs.py` and cover:

- Python syntax (`py_compile`) for tracked PoC scripts
- `package.json`, `Cargo.toml`, `requirements*.txt`, and JSON manifest structure
- JavaScript/module syntax via `node --check` for `*.js`, `*.mjs`, and `*.cjs`
- Shell syntax via `bash -n` for tracked `*.sh` scripts
- `SHA256SUMS.txt` manifest structure, safe repo-local path resolution, referenced-file existence, and checksum integrity
- Per-entry `README.md` presence and root catalog consistency

Run locally:

```bash
python -m unittest discover -s tests -v
python validate_pocs.py
```

CI runs the same suite on every push and pull request (`.github/workflows/validate.yml`).

## Consolidation Check

This section applies to the former standalone repositories listed above by commit hash.
Expand All @@ -87,6 +149,6 @@ Direct entries, including `c-ares-tcp-uaf-calc-poc`, `curl-smtp-expn-recipient-c

## ABUSE

Do NOT, under any circumstances, use any material in this repository maliciously. This is good-faith, open-disclosure vulnerability research intended to get more people interested in exploring this area of cybersecurity.
Do NOT, under any circumstances, use any material in this repository maliciously. This is good-faith, open-disclosure vulnerability research intended to get more people interested in exploring this area of cybersecurity.

Cybercrime is cringe.
2 changes: 1 addition & 1 deletion discord-activity-stock-client-rce-poc/SHA256SUMS.txt
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
c4ed9cfca96fcb747567322e7beb4f8926526245c72e22d4a190ccf061e72588 .gitignore
05d0c62b200ce9737efb64322941f2685c7537295f1691b1ca47222d09a181c3 README.md
e64e9b78f3a7fafeb0534a5bcdfbf170cf1c175393c284db4df8e3901b7c4a51 evidence/verified-stock-run.json
a37a875423978b80d9b1c7545df96769624a37572fd5804b69c10070dfbdb458 exploit.html
5e5403e68f836f579919884696e489666d2d5f71f58bc8b1048375328794ac29 exploit.html
34f53fe856128d9441638755508da6b07a5563e80d894d79b7d67a704abcc47b run.ps1
61a084421bcb96e2c92d19e54a420f8df8e93ae204d184f4e7e095cbf29bdea4 server.js
3d259aea18f6d72ed50a5d574ed10ab08e2db333be801515feceff2469344f88 wasm-module-builder.js
71 changes: 71 additions & 0 deletions docs/architecture.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
# Repository Architecture

This document describes repository-level architecture from the current source code (`validate_pocs.py`, `tests/test_validate_pocs.py`, and `.github/workflows/validate.yml`).

## Components

- **PoC entries (top-level folders)**
- Self-contained exploit research folders.
- Each folder is expected to include a local `README.md`.
- Files may include Python, JavaScript, JSON manifests, Cargo manifests, requirements files, payloads, and evidence.

- **Catalog (`README.md`)**
- Source of truth for listed top-level PoC directories.
- Parsed by `validate_pocs.parse_readme_catalog()`.

- **Validator (`validate_pocs.py`)**
- Discovers target files with repository-relative exclude rules.
- Validates Python syntax (`py_compile`), `package.json`, generic JSON, Cargo TOML, `requirements*.txt`, JavaScript/module syntax (`node --check` for `*.js`, `*.mjs`, `*.cjs`), shell syntax (`bash -n` for `*.sh`), and `SHA256SUMS.txt` integrity manifests.
- Validates per-entry README presence and catalog ↔ directory consistency.

- **Unit tests (`tests/test_validate_pocs.py`)**
- Verifies discovery behavior and validation behavior for repository and fixture repos.
- Imports and exercises validator internals and CLI return behavior.

- **CI (`.github/workflows/validate.yml`)**
- Runs tests and validator on push/pull_request/workflow_dispatch.
- Installs Python and Node in CI to satisfy validator requirements.

## Dependency graph (code-derived)

```mermaid
flowchart LR
subgraph CI[GitHub Actions]
WF[validate.yml]
end
subgraph Validation[Validation pipeline]
UT[tests/test_validate_pocs.py]
VP[validate_pocs.py]
end
subgraph Data[Repository data]
ROOTREADME[README.md catalog]
POCDIRS[top-level PoC directories]
POCREADME[per-entry README.md]
POCFILES[*.py / *.js / *.mjs / *.cjs / *.sh / package.json / Cargo.toml / requirements*.txt / *.json / SHA256SUMS.txt]
end
WF --> UT
WF --> VP
UT --> VP
VP --> ROOTREADME
VP --> POCDIRS
POCDIRS --> POCREADME
POCDIRS --> POCFILES
```

## Runtime/tooling dependencies

- Python 3.11+ (uses `tomllib` from stdlib; CI pins 3.12)
- Node.js for JavaScript syntax checks (`node --check`)
- No third-party Python dependencies for repository validation

## Validation contract

A repository pass requires all of the following:

1. Discoverable files exist and parse/compile correctly per file type.
2. Checksum manifests have valid lines, resolve to tracked files beneath the repository root (whether written as local or repo-relative paths), and match current file bytes.
3. Every top-level PoC directory has a `README.md`.
4. Root catalog rows in `README.md` match top-level PoC directories exactly (no missing/extra/duplicate names).
2 changes: 1 addition & 1 deletion ffmpeg-rasc-dlta-calc-poc/SHA256SUMS.txt
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
673708db6c4a4688b0dd2e997f903820ad49d0a22fe32f016738df31207df405 ffmpeg-rasc-dlta-calc-poc/README.md
15f7f742b2a95ae291edcaee5ec5d77762400a36e9e34fc2cf8b2d6721e58009 ffmpeg-rasc-dlta-calc-poc/README.md
1c2871104b11b13ef03872113466beb7984dc8a6d49cd8150f33ccbb93a3a35a ffmpeg-rasc-dlta-calc-poc/poc/ffmpeg_rasc_dlta_calc_poc.c
6964fcd5c70bd71ac3a15e8e54968d1aaca24490a458c7d954511351c5ae5a11 ffmpeg-rasc-dlta-calc-poc/scripts/build_from_checkout.sh
8e432e3d82695fe9b18c9f6f35ae420778811c5b43e894b0f817cc0bf76d0cae ffmpeg-rasc-dlta-calc-poc/scripts/run_calc_pop.sh
Expand Down
Loading