CVE MAPPING
Safety
Authorized defensive research only: disposable systems, localhost-only services, synthetic data.
- Use a disposable Docker host and synthetic accounts such as
Victim. - Keep GitLab bound to
127.0.0.1:8929; use an SSH tunnel when remote access is needed. - Never expose the vulnerable image publicly or connect it to production data.
- Run only the included benign proof flows against disposable projects/issues.
- Do not add shell execution, destructive deletion, credential collection, or persistence.
- Treat captures and runtime directories as private. Do not publish raw PCAPs.
- Stop and remove containers and their ignored runtime data after the lab.