SoheilKhodayari / JAW
JAW: A Graph-based Security Analysis Framework for Client-side JavaScript
☆105Updated last month
Alternatives and similar repositories for JAW:
Users that are interested in JAW are comparing it to the libraries listed below
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆41Updated last year
- Testability Pattern Catalogs for SAST☆29Updated 10 months ago
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆92Updated last year
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆61Updated 11 months ago
- ☆29Updated 3 months ago
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆71Updated 3 years ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆151Updated 11 months ago
- Artifact for ICSE 2023☆46Updated 2 years ago
- ☆27Updated 2 years ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆46Updated 2 months ago
- Searcher for cross-site leaks (XS-Leaks)☆83Updated 2 years ago
- List of Trusted Types bypasses☆86Updated 9 months ago
- ☆46Updated last year
- ObjLupAnsys is a tool to detect prototype pollution vulnerabilities in Node.js packages. This project is written in Python and JavaScript…☆22Updated 3 years ago
- AutoSpear☆54Updated last year
- A framework for identifying vulnerabilities in VS Code extensions☆16Updated 6 months ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆244Updated 2 months ago
- Awesome MXSS ??☆47Updated 3 months ago
- A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozi…☆84Updated last week
- This repository is a one-stop shop for diving deep into the fascinating world of mXSS (mutations caused by browser quirks in HTML parsing…☆18Updated last month
- A curated list of awesome resources about LLM supply chain security (including papers, security reports and CVEs)☆27Updated last week
- CodeQL zero to hero blog post series challenges☆106Updated last month
- ☆25Updated 11 months ago
- A curated list of awesome browser security learning material.☆137Updated 2 years ago
- XS-Leak Browser Test Suite☆73Updated last year
- The repository has collected about 10,000 malicious pypi packages. This dataset is the work of the ASE 2023 paper "An Empirical Study of…☆73Updated last month
- The source code (including datasets) of V1SCAN (USENIX Security 2023; will be uploaded).☆41Updated last year
- A structure-aware HTTP fuzzing library☆209Updated last month
- Parser utility to generate ASTs from PHP source code suitable to be processed by Joern.☆35Updated 4 years ago