A curated collection of intentionally vulnerable environments for reproducing and analyzing real-world CVEs and security flaws in isolation β all containerized with Docker. Perfect for learning, hands-on experimentation, security research, and practicing security code review.
- CVE-2025-29744 β SQL Injection in
pg-promise(Node.js ORM)
- SWAP β Classic ID swap vulnerability.
- SWAPTWO β ID swap with MD5-hashed file names.
- RacingObject β Race-condition-based IDOR exploiting delayed ownership assignment.
π‘ More labs coming soon...