exploitarium: A GitHub Archive of Unreported Exploit PoCs, Inviting Readers to Claim CVEs
udmrzn · x · 2026-09-04
X users are sharing the GitHub repo bikini/exploitarium (4.3k stars, 1.2k forks): a single archive of public exploit PoCs and vulnerability research writeups.
- Extremely broad coverage: RCEs, escapes and injections across 7zip, AnyDesk, curl, Discord, Docker, FFmpeg, multiple Firefox builds, Ghidra, and Flowise — including an MCP env-variable case-bypass PoC
- The author claims that at posting time none of these have been reported, and openly invites others to report them and claim CVE credit
- Framed as security outreach ("to allure people into the field") with a do-not-abuse caveat, but clearly dual-use
The Flowise MCP PoC is especially relevant to AI infrastructure security.
More from Safety
- Tester: AI-text detector Pangram shows zero false positives, but adversarial rewriting evades it — alex_peys · 2026-09-04
- Scoop: Zuckerberg opposed a national AI regulator in a private call with Trump — GarrisonLovely · 2026-09-04
- OpenAI says GPT-6 Astra shows Critical cyber capabilities, forcing harder ExploitBench evals — SIGKITTEN · 2026-09-04
- Zvi warns Astra's CoT controllability surge could systematically erode AI monitorability — TheZvi · 2026-09-04
- What's the Smallest Chat LLM That Can Validate Against Malicious Prompts? — Brilliant_Criticism3 · 2026-09-04
- Debian Passes General Resolution on LLM Usage, Rebuking Blanket AI-Code Bans — unixterminal · 2026-09-04