Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: etherbeing/cveforge

Security

SECURITY.md

🔒 SECURITY.md

Security Policy for CVE Forge

The integrity and ethical use of the CVE Forge framework are our highest priorities. As a tool focused on security, we take the security of the framework and the responsible behavior of our users and contributors extremely seriously.

1. 🚨 Responsible Disclosure Policy (For the Project Itself)

If you discover a vulnerability within the CVE Forge framework itself (e.g., a critical flaw in the shell interpreter, module loading, or command execution that could lead to unauthorized access or instability), we ask that you report it to us confidentially.

  • DO NOT open a public GitHub Issue.
  • Email: Please send a detailed description of the vulnerability, including steps to reproduce, to [n4b3ts3@gmail.com].
  • Response: We will acknowledge your report within 48 hours and provide a detailed plan for addressing the vulnerability within one week. We follow a standard coordinated disclosure process.

2. 🛡️ User and Contributor Security Guidelines

The use of CVE Forge must be strictly legal and ethical.

  • Authorization is Mandatory: Any use of exploit modules or penetration testing features must be conducted with explicit, written permission from the asset owner.
  • No Unauthorized Targets: Using this framework to target systems, networks, or devices without prior consent is illegal and violates this policy.
  • Malware Policy: All payloads and malware-related components are for authorized countermeasure research and penetration testing within securely isolated environments (e.g., sandboxes, virtual machines). Submission of offensive, deployed, or undocumented malware is strictly prohibited.

3. 📝 Contribution Security Review

Due to the nature of the project:

  • All Pull Requests (PRs) related to exploit modules, commands, or core features undergo a mandatory security review by the core team.
  • We reserve the right to reject any contribution that poses a security risk to the framework, its users, or that violates our ethical use policy.

4. 🔏 PGP Key (Optional but Recommended)

For maximum confidentiality when reporting security issues, you may use our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGjWhzABDADCBDM6WRiZHzAgEQ1VTyGhKjRE12ZipaEdQe8ZSm0MUeZpUcDi
qbyYz+DEBPSC5bi1797uSwJ70UFQs/QuqJ4zSgGMSIHjorcoFxwM19vYW/HA5Cxw
KjY0tDj0kKITofxtVG7KXmgcxziV6icipTVS8ydIi2T3uwveB+fQ+/oXKhmoF/Jt
3eRovxEQMVDDs+mn6IBpTuRXtLfHpkZgjC7F7oVFxNXznJ+5OzUfUGfkIkCdnC1s
+G/XjQPO+7H33QjnOqJcJxxf9gsEbwYG49LOdTGuX/gc9FLDpqw4LHs9yKDJuc3Z
K7P+vdebTuwt6SiU5Sg0OKEZWEB40ps/zXu5inlyEECOckawYDUQXcRSW1icOB6A
MftbB/95UnP/A18zMDBqZcxEDeqTXyMejmKB2v8SPLTkcnz5LK9HbY0IprOK3EtL
gRg1o0LMLIYSu6Y42C1pdZlR3a02eeTZOsx6rWI+DmmCs8P1QQIHRG1ZJZb8ycLr
t5C6uh4Cg6A8dlkAEQEAAbSNIChLZXkgaW50ZW50ZWQgdG8gYmUgdHJhbnNtaXR0
ZWQgZnVsbHkgaW5jbHVkZWQgaXRzIHByaXZhdGUgcGFydCBmb3IgZGVwbG95bWVu
dHMgYW5kIHJldmVhbHMgb2YgZ2l0IHNlY3JldHMgYW5kIG1vcmUpIDxwdWJsaWNA
ZXRoZXJiZWluZy5kZXY+iQHOBBMBCgA4FiEEuw8qUzgK0I0Jejmju715v44bAbEF
AmjWhzACGwMFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQu715v44bAbFuLgv+
N0mG+7Kfy+HaxUyNFNc3phe4HIbvy8Nlk1Q0KWAfmg3Rxx+gt2OoRZyt703fYGEH
ztzrvKwjB0C+I1cWZVCW94S4edowHj6tlLqbe9mAKKP4q6VuIY/nBcVqEu8asPAY
8Uxoc3lUhJ6j1j5eBCQb/9aSFyjZCSeAgNJeXjoJ9IGuSLIrkqS0pukZyQb8UHXt
QFE7BZszqQ2eXmELF3UHaHVXqjJC/9PkqLdsFyekaDYS3893WhmtTxjZqdtmOVvb
04u/V8Y8bw62i8NDcJM2N1xpn4Wrjt5MKAk4DKonkqC2G10I4qVtNwuTKFTEiTtL
2U5UOE8GhPkiq9eP0AjMIgOdDGnTVlYVyI12KmbWMQfGAVx1gbXMtDUKV9FBK4sa
YywWAEfePpA4UKIRVgmKL35O72SuTyvqVHIiagCp15jPeWYW5aoEQyxrd0YEZuV9
/H/RgEBdXv03zAxNX2hdyX17g1BAdD6AEbyRphAr13y2MkBu+vpqra+J7Y2GvB1A
uQGNBGjWhzABDADKQzAIQGyy2xdL+OWaPFLyHAwbVZXorJ/bSEnK3EZDi/RtIrMQ
liRFYKnHXw3YN1UllV9Mj/hhAXKoqqOKEquYkqF5KaZNJXu4pjo2JfLByhBIBP9a
FvIWHV/ySmdq5mc0QVD3xsarilfGBrtvrRypxJFEfFA4sZYHufCnCw5oV7OFt1MC
StAA7xWNgwwki7WrxdXSH4OjCF4qSp7aXsMp+ELDFmx9NyHJa/Iy+lLnrtyPjYGJ
im0cUCPMEnThwqZi0ccfHln7lV7cS/4D3FSJNpxBBLYMp4waiaaFwQgSdzz3X4Qs
D/k8dYPf9SV2IFV+dHVJgamCKYhV/RwoNVENRgrJQfbifE74n8wTgXUPR1DXPaAo
PynM1m35b8o4k38lBZa4oKtAb7Jq+NxZNqMg161Xm5iEHpLv5SL7tkYx7aB+LQJ+
2SZMVA5cAps0AZEyPfjwA0Zz5+2maDTMWJRetmIu2Ttu9S9fBx0fpkqsI1iWGlRH
KsBkDvI6Chgd2wUAEQEAAYkBtgQYAQoAIBYhBLsPKlM4CtCNCXo5o7u9eb+OGwGx
BQJo1ocwAhsMAAoJELu9eb+OGwGxLT0MALZIdYczT57DM5j+2sWvw5MYCBzGJLRH
JGvT1Kr0vqrL9e8MmuYgcXqSEZTvWCOZeI095MgAivlsgIcdO4HGEZ+0P1DalVbj
iu6NrBpE//PE7nto84QSX0NgmjAQV1FyLt5UXzjK1dq/ohqq/Zi62uJGW7Ksq394
7quI34J3UHbS6dn6UYaMA2FU06USC2XMmcS5EDNqA7UQfqgAitphzhDjU9qj3b4g
BZtSXzW+oZ0Y6J8SGsFn9gPAN7gXTP/h7jm7zfiyUnqvniTlubIJMHWjWHQ4Knbt
9O/bKU79j24vsamzIdwqMRIxTyWZ63oqmjyQx+9NZObDHR1AR5R7g2iYDp35J38H
yLYvoOoXLHAhWZ+2oprEks4U9zfY/KbagqsoE0aWt4HqijwwCf5gwAqtTA0O1Meo
ztYxm9E+V7EUAo8EbRJzcPFup2VpMFDhwOJb0BMFkmH6F9cmRz7SqkWYD4afaGQ9
1dF5ZmESy/OZ7Lc5Bjv+5Xvfxy+KW2K9Nw==
=CIaQ
-----END PGP PUBLIC KEY BLOCK-----

5. 📢 The Principle of Defense and Open Access

CVE Forge is fundamentally a tool for digital defense, education, and empowering self-determination. We provide open-source resources to security practitioners globally to test, secure, and understand the vulnerabilities within their own authorized systems, networks, and informational environments. Our mission is to strengthen digital resilience and ensure that information access and security are available to all, regardless of geopolitical climate.

We strongly oppose the use of our framework for offensive cyber-aggression or unauthorized intrusion. The responsibility for ensuring authorization and adhering to the principle of Harm Minimization rests entirely with the user.

There aren't any published security advisories