Skip to content
View kOaDT's full-sized avatar
🍉
🍉
  • France

Block or report kOaDT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kOaDT/README.md

AppSec & Web Developer

Header

TryHackMe   Root-Me


CVE Reported (1)
CVE Score Date Description
CVE-2026-32255 8.6 2026-03-19 Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch() server-side, and returns the full response body. An unauthenticated attacker can use this to make HTTP requests from the server to internal services, cloud metadata endpoints, or private network resources. This issue has been fixed in version 0.5.5. To workaround this issue, block or restrict access to /api/download/attatchment at the reverse proxy level (nginx, Cloudflare, etc.).
CVE Proof of Concepts (3)
CVE Description 🍴 👁️ 📥
CVE-2025-55182 This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell. 15 3 5489 1646
CVE-2025-29927 This repository contains a POC and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware. 8 3 2239 830
CVE-2026-32255 This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an open-source project management tool. 2 - 1004 316
Projects (5)
Project Description 🍴 👁️ 📥
oss-oopssec-store Security training for the apps you actually ship. Open your browser and start hacking. 34 45 5746 52244
cyber-bot Threat intelligence platform: RSS aggregation, NVD CVE tracking, ENISA EUVD, databreaches, ... 5 1 261537 2020
hate-crimes-map This project aims to visualize hate crime data to bring visibility to crimes that are often invisible or normalized by society. 3 - 154 491
awesome-pentest-tools Open-source offensive security tools, plus a vendor-agnostic AI agent that runs authorized pentest engagements using only tools from this list. 3 2 31 237
crack-hash A fast, multi-threaded hash cracking tool written in Rust. This tool performs dictionary attacks against hashed passwords. 2 - 76 55
OSS Contributions (20)
Repository Description 🍴
kanbn/kan The open source Trello alternative. 5325 438
ThePorgs/Exegol Fully featured and community-driven hacking environment 3029 280
beelzebub-labs/beelzebub A secure low code deception runtime framework, leveraging AI for System Virtualization. 2135 206
OWASP/www-community OWASP Community Pages are a place where OWASP can accept community contributions for security-related content. 1396 842
OWASP/www-project-vulnerable-web-applications-directory The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available. 90 51
nilbuild/developer-roadmap Interactive roadmaps, guides and other educational content to help developers grow in their careers. 364018 44762
usebruno/bruno Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia) 46231 2766
enaqx/awesome-pentest A collection of awesome penetration testing resources, tools and other shiny things 26847 4906
qazbnm456/awesome-web-security 🐶 A curated list of Web Security materials and resources. 13661 1811
infoslack/awesome-web-hacking A list of web application security 7226 1354
satnaing/astro-paper A minimal, accessible and SEO-friendly Astro blog theme. 4937 1057
husnainfareed/awesome-ethical-hacking-resources 😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing. 3693 559
lingdojo/kana-dojo Aesthetic, minimalist platform for learning Japanese inspired by Duolingo and Monkeytype, built with Next.js and sponsored by Vercel. Beginner-friendly with plenty of good first issues - all contributions are welcome! 3155 2987
fabionoth/awesome-cyber-security A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. 1924 264
vavkamil/awesome-vulnerable-apps Awesome Vulnerable Applications 1462 226
kaiiyer/awesome-vulnerable A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB. 1373 227
okhosting/awesome-cyber-security A curated list of cyber security resources and tools. 692 113
Grafikart/Grafikart.fr Dépôt pour la nouvelle version de Grafikart.fr 691 188
noraj/rawsec-cybersecurity-inventory An inventory of tools and resources about CyberSecurity that aims to help people to find everything related to CyberSecurity. 342 75
secnotes/awesome-cybersecurity A collection of awesome github repositories about security 77 9
Publications (1)
Title Platform Category Date
MCP Tool Poisoning OWASP article 2026-03-26
Github Metrics

TryHackMe Stats
Global Rank Top Streak
#12843 1% 726 days
TryHackMe Badges (49)
  • Networking NerdCompleting the 'Network Fundamentals' module
  • 7 Day StreakAchieving a 7 day hacking streak
  • WebbedUnderstands how the world wide web works
  • World Wide WebCompleting the 'How The Web Works' module
  • cat linux.txtBeing competent in Linux
  • 30 Day StreakHacking for 30 days solid
  • OWASP Top 10Understanding every OWASP vulnerability
  • Hash CrackerCracking all those hashes
  • MetasploitableContains the knowledge to use Metasploit
  • BlueHacking into Windows via EternalBlue
  • Cyber ReadyUnderstanding impact of training on teams
  • Sword ApprenticeCompleting the SQLMap room
  • Shield ApprenticeCompleting the FlareVM room
  • 90 Day StreakHacking for 90 days in a row
  • Linux PrivEscMastering Linux Privilege Escalation
  • Pentesting PrinciplesCompleting the 'Introduction to Pentesting' module
  • Intro to Web HackingCompleting the 'Introduction to Web Hacking' module
  • Advent of Cyber 2024Completing Advent of Cyber 2024!
  • Burp'edCompleting the Burp Suite module
  • 180 Day StreakHacking for 180 days in a row
  • Authentication StrikerUsed the Hammer to bypass authentication
  • SQL SlayerConquered Advanced SQL Injection
  • System SnifferCompleted the File Path traversal room
  • OhSINTCompleting the OhSINT room
  • Client-Side ChampSuccessfully exploited client-side vulnerabilities
  • Introduction to Security EngineeringCompleted the Security Engineer Intro room!
  • Calculated Risk — _Completed the Risk Management room! _
  • 3 Day StreakAchieving a 3 day hacking streak
  • Network and System SecurityFinished the Auditing and Monitoring room!
  • Software Security — _Completed the OWASP API Security Top 10 rooms! _
  • 365 Day StreakHacking for 365 days in a row
  • The Course AwakensFinishing the first room in the DevSecOps path!
  • Just have to deal with it — _Successfully managed a cyber crisis! _
  • Raffle RoyaltyParticipating in Hack2Win 2025!
  • /opt/m0th3rFinishing Mother’s Secret!
  • Skilled NavigatorFinishing the Eviction challenge!
  • First Step into SOCExplored emerging threats and SOC response
  • SOC ApprenticeExplored how a SOC team operates from inside
  • First alert closedClosing your first alert
  • First scenario completedCompleting your first scenario
  • 100% true positive rateAchieving 100% true positive rate in a scenario
  • 500 Day StreakHacking for 500 days in a row
  • Tooling SpecialistAdept in creating custom offensive tooling
  • Advent of Cyber 2025Completing Advent of Cyber 2025!
  • Model CompromiseCompleted the LLM Attacks Module
  • Session HeldCompleting 4 weekly missions in a row!
  • Security AwarenessCompleting the cyber security awareness module
  • Adversarial Defence OpsTrained to Defend, Built to Learn.
  • AI OdysseyTaking part in the AI Odyssey event!
TryHackMe Completed Rooms (346)
# Room Difficulty
1 Crack the hash easy
2 Kali Machine easy
3 Pickle Rick easy
4 Blue easy
5 OhSINT easy
6 Basic Pentesting easy
7 Vulnversity easy
8 Simple CTF easy
9 Kenobi easy
10 tmux easy
11 Steel Mountain easy
12 Hacking with PowerShell easy
13 Bebop easy
14 DVWA easy
15 Agent Sudo easy
16 LazyAdmin easy
17 Geolocating Images easy
18 Sudo Security Bypass info
19 Introductory Networking easy
20 Common Linux Privesc easy
21 Google Dorking easy
22 Network Services easy
23 Introductory Researching easy
24 What the Shell? easy
25 Hashing - Crypto 101 medium
26 Linux PrivEsc medium
27 Upload Vulnerabilities easy
28 Encryption - Crypto 101 medium
29 Bounty Hacker easy
30 OWASP Juice Shop easy
31 NIS - Linux Part I easy
32 Overpass easy
33 Network Services 2 easy
34 Python Basics easy
35 RootMe easy
36 Physical Security Intro easy
37 The Hacker Methodology easy
38 Tutorial easy
39 Getting Started easy
40 MITRE medium
41 Starting Out In Cyber Sec easy
42 Nmap easy
43 Introduction to Flask easy
44 John the Ripper: The Basics easy
45 Cryptography for Dummies easy
46 How to use TryHackMe easy
47 Linux Fundamentals Part 1 info
48 Linux Fundamentals Part 2 info
49 How Websites Work easy
50 Linux Fundamentals Part 3 info
51 Putting it all together easy
52 DNS in Detail easy
53 HTTP in Detail easy
54 Windows Fundamentals 1 info
55 Windows Fundamentals 2 info
56 Learn and win prizes info
57 SQLMAP easy
58 What is Networking? info
59 Intro to LAN info
60 OSI Model info
61 Packets & Frames info
62 Extending Your Network info
63 Learning Cyber Security easy
64 Windows Fundamentals 3 info
65 Linux Privilege Escalation medium
66 Walking An Application easy
67 Pentesting Fundamentals easy
68 Principles of Security info
69 Metasploit: Exploitation easy
70 Content Discovery easy
71 Subdomain Enumeration easy
72 Authentication Bypass easy
73 Junior Security Analyst Intro easy
74 Passive Reconnaissance easy
75 Active Reconnaissance easy
76 Nmap Live Host Discovery medium
77 Nmap Basic Port Scans easy
78 Nmap Advanced Port Scans medium
79 Metasploit: Introduction easy
80 IDOR easy
81 Vulnerabilities 101 easy
82 Metasploit: Meterpreter easy
83 Intro to SSRF easy
84 Pyramid Of Pain easy
85 Intro to Cross-site Scripting easy
86 Nmap Post Port Scans medium
87 Cyber Kill Chain easy
88 Diamond Model easy
89 Security Awareness info
90 Vulnerability Capstone easy
91 Exploit Vulnerabilities easy
92 Protocols and Servers easy
93 SQL Injection medium
94 Command Injection easy
95 Net Sec Challenge easy
96 File Inclusion medium
97 Protocols and Servers 2 medium
98 Common Attacks easy
99 Red Team Fundamentals easy
100 Pwnkit: CVE-2021-4034 info
101 Threat Intelligence Tools easy
102 Intro to Digital Forensics easy
103 Introduction to DevSecOps medium
104 Operating System Security easy
105 Lo-Fi easy
106 Network Security easy
107 Web Application Security easy
108 Unified Kill Chain easy
109 Spring4Shell: CVE-2022-22965 info
110 SSDLC medium
111 Security Operations easy
112 Careers in Cyber info
113 Windows Privilege Escalation medium
114 Wireshark: The Basics easy
115 Intro to Cyber Threat Intel easy
116 Introduction to SIEM easy
117 Intro to Containerisation easy
118 Active Directory Basics easy
119 Microsoft Windows Hardening easy
120 Security Principles easy
121 Atlassian CVE-2022-26134 easy
122 Secure Network Architecture medium
123 Active Directory Hardening medium
124 Introduction to Cryptography medium
125 Network Security Protocols medium
126 OWASP API Security Top 10 - 2 medium
127 OWASP API Security Top 10 - 1 medium
128 Intro to Cloud Security easy
129 Linux System Hardening medium
130 Virtualization and Containers easy
131 Vulnerability Management medium
132 DAST medium
133 Weaponizing Vulnerabilities medium
134 Identity and Access Management easy
135 Network Device Hardening medium
136 Threat Modelling medium
137 Governance & Regulation easy
138 Mother's Secret easy
139 Security Engineer Intro easy
140 SAST medium
141 Risk Management easy
142 Broken Access Control easy
143 Logging for Accountability easy
144 Traverse easy
145 Auditing and Monitoring easy
146 Intro to IR and IM easy
147 Becoming a First Responder info
148 Cyber Crisis Management easy
149 W1seGuy easy
150 Burp Suite: The Basics info
151 Burp Suite: Repeater info
152 Burp Suite: Intruder medium
153 Burp Suite: Other Modules easy
154 Burp Suite: Extensions easy
155 Eviction easy
156 Summit easy
157 Light easy
158 HTTP Request Smuggling easy
159 The Witch's Cauldron easy
160 Confluence CVE-2023-22515 easy
161 SSRF medium
162 Become a Hacker easy
163 The Sticker Shop easy
164 File Inclusion, Path Traversal medium
165 CSRF medium
166 XSS easy
167 CORS & SOP easy
168 Prototype Pollution medium
169 Snyk Open Source easy
170 Include medium
171 Moniker Link (CVE-2024-21413) easy
172 Snyk Code easy
173 Race Conditions medium
174 LDAP Injection easy
175 Whats Your Name? medium
176 DOM-Based Attacks easy
177 XXE Injection medium
178 Insecure Deserialisation medium
179 Windows Command Line easy
180 Search Skills easy
181 Server-side Template Injection medium
182 JWT Security easy
183 Nmap: The Basics easy
184 Networking Concepts easy
185 Tcpdump: The Basics easy
186 Networking Essentials easy
187 Networking Core Protocols easy
188 Networking Secure Protocols easy
189 Advanced SQL Injection medium
190 Incident Response Fundamentals easy
191 ORM Injection medium
192 NoSQL Injection easy
193 Logs Fundamentals easy
194 Enumeration & Brute Force easy
195 SOC Fundamentals easy
196 Digital Forensics Fundamentals easy
197 Session Management easy
198 Injectics medium
199 Firewall Fundamentals easy
200 OAuth Vulnerabilities medium
201 IDS Fundamentals easy
202 Multi-Factor Authentication easy
203 Vulnerability Scanner Overview easy
204 Hammer medium
205 CyberChef: The Basics easy
206 Public Key Cryptography Basics easy
207 Cryptography Basics easy
208 Hashing Basics easy
209 CAPA: The Basics easy
210 Windows PowerShell easy
211 FlareVM: Arsenal of Tools easy
212 REMnux: Getting Started easy
213 Linux Shells easy
214 Length Extension Attacks medium
215 Insecure Randomness easy
216 Gobuster: The Basics easy
217 Training Impact on Teams info
218 SQLMap: The Basics easy
219 Advent of Cyber 2024 easy
220 JavaScript Essentials easy
221 Web Application Basics easy
222 SQL Fundamentals easy
223 Shells Overview easy
224 Padding Oracles medium
225 Breaking Crypto the Simple Way easy
226 Phishing Basics easy
227 Custom Tooling Using Python easy
228 Custom Tooling using Burp hard
229 Tooling via Browser Automation easy
230 SOC L1 Alert Triage easy
231 SOC L1 Alert Reporting easy
232 Cyber Kill Chain medium
233 SOC Workbooks and Lookups easy
234 Attacking ECB Oracles hard
235 Next.js: CVE-2025-29927 easy
236 SOC Metrics and Objectives easy
237 The Building Blocks of AI easy
238 CAPTCHApocalypse medium
239 Erlang/OTP SSH: CVE-2025-32433 easy
240 Writing Pentest Reports easy
241 AI Forensics medium
242 Extract hard
243 Cipher's Secret Message easy
244 Evil-GPT easy
245 Evil-GPT v2 easy
246 Sequence medium
247 Roundcube: CVE-2025-49113 easy
248 ContAInment medium
249 Chaining Vulnerabilities easy
250 Voyage medium
251 Humans as Attack Vectors easy
252 Systems as Attack Vectors easy
253 SOC Role in Blue Team easy
254 Web Security Essentials easy
255 Hack2Win: How you can grab extra tickets info
256 Introduction to EDR easy
257 Input Manipulation & Prompt Injection easy
258 Data Integrity & Model Poisoning medium
259 LLM Output Handling and Privacy Risks easy
260 IDOR - Santa’s Little IDOR medium
261 Obfuscation - The Egg Shell File medium
262 XSS - Merry XSSMas easy
263 Passwords - A Cracking Christmas easy
264 SOC Alert Triaging - Tinsel Triage medium
265 Splunk Basics - Did you SIEM? medium
266 Phishing - Merry Clickmas easy
267 Prompt Injection - Sched-yule conflict easy
268 Linux CLI - Shells Bells easy
269 YARA Rules - YARA mean one! medium
270 Forensics - Registry Furensics medium
271 Exploitation with cURL - Hoperation Eggsploit easy
272 ICS/Modbus - Claus for Concern medium
273 Race Conditions - Toy to The World easy
274 Network Discovery - Scan-ta Clause easy
275 Containers - DoorDasher's Demise medium
276 CyberChef - Hoperation Save McSkidy medium
277 Phishing - Phishmas Greetings medium
278 AI in Security - old sAInt nick easy
279 Malware Analysis - Malhare.exe easy
280 C2 Detection - Command & Carol medium
281 AWS Security - S3cret Santa easy
282 Malware Analysis - Egg-xecutable medium
283 Web Attack Forensics - Drone Alone medium
284 Cloud Security Pitfalls easy
285 Juicy medium
286 Advent of Cyber Prep Track easy
287 OWASP Top 10 2025: Insecure Data Handling easy
288 Django: CVE-2025-64459 easy
289 BankGPT easy
290 HealthGPT easy
291 React2Shell: CVE-2025-55182 easy
292 Virtualisation Basics easy
293 Operating Systems: Introduction easy
294 Linux CLI Basics easy
295 Data Representation easy
296 Data Encoding easy
297 JavaScript: Simple Demo medium
298 Python: Simple Demo easy
299 LLM Security medium
300 Windows Basics easy
301 Cloud Computing Fundamentals easy
302 Windows CLI Basics easy
303 The CIA Triad easy
304 Database SQL Basics easy
305 Recruit medium
306 Cryptography Concepts easy
307 Client-Server Basics easy
308 Become a Hacker easy
309 Become a Defender easy
310 n8n: CVE-2025-68613 easy
311 Offensive Security Intro easy
312 Inside a Computer System easy
313 GeoServer: CVE-2025-58360 medium
314 Computer Types easy
315 Dive Into Pentesting easy
316 API Pentesting easy
317 Prompt Engineering easy
318 AI Models & Data medium
319 Walking An Application easy
320 Defensive Security Intro info
321 AI Threat Modelling medium
322 Securing AI Systems medium
323 CSRF Introduction easy
324 AI System Reconnaissance medium
325 Penetration Testing Frameworks easy
326 Guided Pentest: Infrastructure easy
327 XSS Introduction medium
328 SQL Injection Introduction easy
329 Guided Pentest: Web easy
330 Web Server Attacks - I medium
331 AI Threat Modelling Assessment easy
332 AI Security Path Ticketing Event info
333 Web Server Attacks - II medium
334 Broken Authentication easy
335 Modern Web Stacks easy
336 Content Discovery easy
337 The Concierge Knows Too Much easy
338 Room 404 easy
339 Complimentary easy
340 Packed Light easy
341 Beach Bar easy
342 Overheard at Breakfast easy
343 Do Not Disturb medium
344 Towel on the Sunbed medium
345 CryptoCabana medium
346 The Hollow Shell medium
Certificates (123)

Pinned Loading

  1. oss-oopssec-store oss-oopssec-store Public

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript 34 45

  2. OWASP/www-community OWASP/www-community Public

    OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

    HTML 1.4k 842

  3. ThePorgs/Exegol ThePorgs/Exegol Public

    Fully featured and community-driven hacking environment

    Python 3k 281

  4. OWASP/www-project-vulnerable-web-applications-directory OWASP/www-project-vulnerable-web-applications-directory Public

    The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.

    HTML 90 51

  5. poc-cve-2025-55182 poc-cve-2025-55182 Public

    This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell.

    TypeScript 15 3

  6. nilbuild/developer-roadmap nilbuild/developer-roadmap Public

    Interactive roadmaps, guides and other educational content to help developers grow in their careers.

    TypeScript 364k 44.8k