> cat /dev/github | grep security-tools
discovered 11 Aug 2026

Windfall

Ruby ★ 18 via github-topic
→ View on GitHub
Windfall is an exploitation framework that targets critical vulnerabilities in Windmill and Nextcloud Flow, specifically focusing on unauthenticated path traversal and authenticated SQL injection vulnerabilities. Its primary use case is to demonstrate how these vulnerabilities can lead to credential leaks and remote code execution, thereby enabling an attacker to exploit the affected systems. Notable features include a comprehensive assessment of the vulnerabilities' impact with high CVSS scores and detailed analysis of attack vectors, enhancing the tool's utility for security researchers and penetration testers.