exploitarium

A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.

48 articles 4.7k View on GitHub ↗
48 articles
Where to Find the QEMU CXL Type-3 Mailbox Escape PoC: Complete Exploitarium Guide

Find the QEMU CXL Type-3 Mailbox Escape PoC in the bikini/exploitarium GitHub repository. Get the complete exploitarium guide and explore the vulnerability.

how-to-guide
Sep 7, 2026
Key Files for QEMU CXL Type-3 Mailbox Exploitation in Exploitarium

Explore the 7 key Exploitarium files crucial for QEMU CXL Type-3 mailbox exploitation. Understand the build and execution process for a successful guest-to-host escape.

deep-dive
Sep 7, 2026
How to Trigger libc::system on QEMU Host from Guest: CXL Type-3 Mailbox Exploit

Learn how to trigger libc system on QEMU host from guest using a CXL Type-3 mailbox exploit. Execute arbitrary commands by leveraging an out-of-bounds read vulnerability. Proof of concept available.

exploit-guide
Sep 7, 2026
How to Build the QEMU CXL PoC with build.sh

Easily build the QEMU CXL PoC with build.sh. Automate compilation of bootloader and payload, creating a bootable poc.img for QEMU.

how-to-guide
Sep 7, 2026
What Is the Purpose of stage2.c in the QEMU CXL Exploit?

Discover the purpose of stage2.c in the QEMU CXL exploit. This code manipulates the CXL Type-3 mailbox interface to trigger host memory corruption and achieve arbitrary code execution.

deep-dive
Sep 7, 2026
How to Use the QEMU CXL PoC Bootloader: Complete Setup and Execution Guide

Learn how to use the QEMU CXL PoC bootloader to demonstrate CXL mailbox escape vulnerabilities. This guide covers setup and execution for the two-stage bootloader.

how-to-guide
Sep 7, 2026
How to Exploit the CXL SET_FEATURE Handler Vulnerability in QEMU: A Complete Guide

Learn to exploit the QEMU CXL SET_FEATURE handler vulnerability. Gain guest-to-host escape and execute arbitrary code with this comprehensive guide.

how-to-guide
Sep 7, 2026
How to Exploit the CXL GET_LOG Handler Vulnerability in QEMU: A Full Chain Guide

Exploit the CXL GET_LOG handler vulnerability in QEMU with this full chain guide. Learn to leak host pointers and achieve arbitrary code execution in the QEMU host process.

how-to-guide
Sep 7, 2026
QEMU CXL Guest-to-Host Code Execution Vulnerability: Technical Analysis of the Type-3 Mailbox Escape

Uncover the QEMU CXL guest-to-host code execution vulnerability. Learn how two flaws in mailbox command handlers allow VM guests to run arbitrary commands on the host.

technical-analysis
Sep 7, 2026
How to Escape QEMU CXL Type-3 Mailbox: A Full Exploit Walkthrough

Learn how to escape the QEMU CXL Type-3 mailbox by chaining an out-of-bounds read with an unbounded write to execute arbitrary host code. Full exploit walkthrough.

exploit-walkthrough
Sep 7, 2026
Discord IPC Calls for RCE: Technical Analysis of the bikini/exploitarium Exploit

Discover how Discord IPC calls enable RCE. Technical analysis of the bikini exploitarium exploit reveals attacker control via DISCORD_SETTINGS_SET and DISCORD_APP_RELAUNCH.

deep-dive
Sep 7, 2026
How to Run the Discord RCE Exploit with run.ps1: A Complete Guide

Learn to run the Discord RCE exploit with run.ps1. Validate hashes, set your public origin, and let the PowerShell script manage the Node.js server and Discord settings restoration for you.

how-to-guide
Sep 7, 2026

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →