Classroom Glossary Public page

ADV-102

ADV-102 is the LLM-era variant of ADV-101's CVE-to-Tool pedagogy. The anchor target is CVE-2025-65106 (LangChain Jinja2 SSTI). Over ten weeks you reproduce the CVE end-to-end on a controlled local install, build a defensible reproduction tool that detects vulnerable LangChain versions, reproduce the Go cousin (CVE-2025-9556 in Gonja), and ship a coordinated-disclosure-style report.

Start here: ADV-102 Course Outline →

Overview

Weekly modules

Labs

Classroom tools and references

ADV-102 leans on the academy classroom for the OWASP taxonomy work and the pcap-tools wiretap surface for the Module 2 LangChain trace lab. The reproduction-tool work happens in your local Python environment with pinned LangChain.