Snyk Labs

Featured article
Same href, different syntax: XSS across content parsers
Catalin Iovita
We’ll explore how URL handling works across Markdown parsers and math renderers, and why validation order matters. We'll dig into a bypass in Goldmark, a popular Go Markdown parser, and see how math rendering can introduce a separate attack surface.
Latest Demos and Research
Step into the Lab
Get updates on future incubations or apply to co-build with us.
Featured Video
Vibe Coding with Claude Agentic AI Tool
Experiments
Where security meets curiosity
Explore projects from Snyk Labs
ai-bom-scan
Python
A tool to scan Snyk AI-BOMs for specific components in Snyk organizations
March 10, 2026
7
10
0
ai-promoter
Python
A simple web application that makes it easy for employees at your company to see and promote content you're creating!
October 30, 2025
3
1
0
mcp-server-nodejs-api-docs
JavaScript
MCP Server for the Node.js API documentation
March 14, 2026
6
4
0









