Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

CVE Forge: A Unified, Actionable Penetration Testing Framework

Build and Deploy to PyPI

CVE Forge is a framework inspired by metasploit aiming to focus on real life scenarios and help pentesters all around the world to be able to find peace by providing them all the tools anyone really needs, the Forge is not about working with outdated vulnerabilities that we know won't work, but rather the Forge focuses on actionable vulnerabilities and establishes a standardized methodology for responsible vulnerability disclosure and exploit development within a framework.

Why this matter?

When starting my career as a pentester and bug hunter I had found that we need a lot of tools, for recoignance, osint, enumeration, exploitation and much more, but what is actually hilarious is the fact that Kali linux or Black Arch does have a lot of tools but no tool that present them all together. Hopefully and perhaps like a dream someday the Kali and BlackArch team will include this inside their built-in tools, but still the goal of this tools is more than engineering all pentesting tools together but actually leveraging the speed for which a pentester developes a ZDE and make a report out of it.

Code of conduct

Even though the actual extended code of conduct is in here is important to understand the next lines described below very clear.

  • 1st. The Software Developer and contributors of this framework do not make themselves responsible for any wrongdoing resulting on the use of the provided framework.
  • 2nd. Zero-Day Policy: Do not submit Zero-Day Exploits (ZDEs) as Pull Requests (PRs). Responsible disclosure to the vendor must be completed before any related exploit code can be considered for inclusion. Use the framework's local testing features for development purposes only.
  • 3rd. ANY pentesting activity and exploitation of ANY vulnerability on unauthorized area is considered to be ILLEGAL and can be subjected to legal actions against yourself, avoid taking unnecessary risks, for that purpose we provide playgrounds and for real life jobs you can find in the Forge website references to bounty programs like HackerOne, Google or Meta bounty programs.

Install

pip install cveforge
cveforge --help
cveforge echo hello there
cveforge # to run interactively

Quickstart

NOTE: This is a TODO meaning is YET to be implemented

uv init # helps you to work in a virtualenv
uv add cveforge # add the cveforge dependency
uv run cveforge scaffold payload --verbose-name WannaCry # add to the forge DB the path to the current project
uv run cveforge scaffold exploit --verbose-name "RSA Cracking" --cve-name cve_2025_0002 # add to the forge DB the path to the current project
uv run cveforge scaffold command --verbose-name "sftp"# add to the forge DB the path to the current project
uv run cveforge # now whenever we modify the payload, the exploit or the command project the cveforge self-refresh

Developing a Malware or Payload

Please note that even though this software allows to create and use malware is intended for authorized pentesting only, with the idea in mind of helping malware develop is not causing unauthorize damage but quickly letting clients know how much can impact a vulnerability into their system.

PR including malware WON'T be merged instead malware development is exclusive for the team responsible of developing this software as countermeasure for safe usage is to be taken (NOTE: this can change in the future when we run this software in an isolated environment)

Developing a command

As you may have noticed this project is a shell like software, you can use command like ping, ip etc... with the only caveat that all commands are to be made using python, even though we support payload development with Rust, we won't be integrating with Rust for exploits or command as this doesn't offer any benefit except for speed AFAIC.

Once you do the quickstart step for developing a command you'd have two pieces of structures a ForgeParser and a decorated function.

The command entrypoint

fromcveforgeimporttcve_commandfromcveforgeimportContextimporttyperimportlogging@tcve_command()defyour_command_name(my_flag: str=typer.Argument()): # WE NOW SUPPORT TYPER!!!context: Context=Context() # store general program datalogging.info("Running your command with flag '%s'", my_flag)

Usage:

your_command_name "CVE Forge is amazing!!!"# output: info: Running your command with flag 'CVE Forge is amazing!!!'

Developing an Exploit or PoC for CVEs

Developing an exploit is just like creating a command but rather than using the @tcve_command we use the @tcve_exploit like follows:

fromcveforgeimporttcve_exploit@tcve_exploit(categories=["cve", "privilege escalation"])defexploit_name(**kwargs):
pass

Note the categories is also a possible command for the @tcve_command decorator, is useful for allowing the user to search with different queries for your command

About

CVE Forge is a unified, actionable penetration testing framework

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages