Skip to main content

atomicvulns — a web security lab with one vulnerability per app (OWASP Top 10 2021, open source)

0
Medium
Published: 09/11/2026 (09/11/2026, 20:12:37 UTC)
Source: Reddit ExploitDev

Description

atomicvulns is an open-source educational project providing a collection of small, intentionally vulnerable web applications, each demonstrating a single OWASP Top 10 2021 vulnerability. It includes 38 isolated apps ('atoms'), each with a vulnerable and fixed version, plus walkthroughs for exploitation and remediation. The project is designed for pentest and AppSec learners to study and practice exploiting and fixing common web vulnerabilities in a focused, hands-on manner. It is not a vulnerability or exploit itself but a learning tool.

Reddit Discussion

r/hacking·posted by u/keotl
00

I spent the last few months building a personal project and it just hit v1.0, so I figured I'd share it here.

atomicvulns is a collection of intentionally vulnerable web apps, but with a different idea: each app isolates a single vulnerability, nothing more. Instead of one big app full of flaws (like DVWA or Juice Shop), each exercise here is small and focused — you read the code, see the cause, exploit it, and compare it against the fixed version sitting right next to it. Short enough to finish one in a single sitting.

Each "atom" ships with the vulnerable app, the fixed app, a commented diff between the two, and a step-by-step walkthrough of the exploit. v1.0 covers all 10 OWASP Top 10 2021 categories — 38 atoms total.

It's aimed at people studying pentest / AppSec who already know the HTTP and terminal basics. Burp Suite is the primary tool across all the walkthroughs.

A few details:

  • Open source (MIT).
  • Bilingual — all docs in English and Portuguese (I couldn't find focused material like this for PT-BR learners, so I wrote both).
  • Solo project, built by me. The goal was a place where each flaw is clear and isolated — the material I wish I'd had while learning web pentest.
  • Built with AI as a pair, with every atom validated by me running the exploit by hand.

Built it for myself, but now that it's done, if it helps someone else along the way, great.

🔗 https://github.com/doretox/atomicvulns

Feedback welcome — happy to hear what's missing or what could be clearer.

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 08:17:09 UTC

Technical Analysis

atomicvulns is a web security lab project that isolates one vulnerability per small web application, covering all OWASP Top 10 2021 categories with 38 distinct apps. Each app includes a vulnerable version, a fixed version, a commented diff, and a step-by-step exploit walkthrough. The project is intended for pentesting and application security education, emphasizing clarity and focus on individual flaws rather than large monolithic vulnerable apps. It is open source under the MIT license and uses Docker for easy local deployment. The project does not represent a security threat or vulnerability in itself but serves as a training resource.

Potential Impact

There is no direct security impact or threat from atomicvulns itself, as it is a controlled educational environment meant to be run locally and not exposed to the internet. The project facilitates learning about vulnerabilities but does not introduce new vulnerabilities into production environments.

Defensive Guidance

No mitigation is required as atomicvulns is an educational tool designed to be run locally for learning purposes. Users should ensure they do not expose these intentionally vulnerable apps to untrusted networks or the internet. Follow best practices by running the apps only on localhost as recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ExploitDev+pwned+hacking
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":41,"reasons":["external_link","newsworthy_keywords:vulnerability,rce","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["vulnerability","rce"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa50a7f55bf5e2cf50e0257

Added to database: 09/12/2026, 08:17:03 UTC

Last enriched: 09/12/2026, 08:17:09 UTC

Last updated: 09/13/2026, 03:31:35 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses