Browser-only pyjail payload generator. Zero backend, zero execution — pure string construction.
PyBreak takes intended Python code and jail restrictions, then generates payload variants that bypass those restrictions. All generation runs client-side via TypeScript string manipulation — no eval(), no new Function(), no server calls.
Live demo: yuzu-octopus.github.io/PyBreak
- 20 one-shot generators across 4 categories — encoding (base64, hex, octal, unicode), character/syntax bypass, composite multi-technique, and advanced CTF patterns
- Multi-strategy solver — runs 4 independent strategies (DirectRCE one-liners, env manipulation, interactive escapes, recursive gadget resolver) and merges results
- 180+ gadget chain finder — Typhon-style recursive dependency resolver with 7 categories covering Python 3.9–3.13, 26 builtins recovery paths, subclass walk variants across 41 indices
- DirectRCE strategy — self-contained one-liners like
help(),breakpoint(),exec(input())for jails that leave builtins accessible - Interactive escape strategy —
help()→ pdb andbreakpoint()→ pdb techniques (opt-in, requires stdin) - Env manipulation strategy — PYTHONINSPECT, BROWSER+antigravity, PYTHONSTARTUP tricks
- Typhon-style input API — paste raw Typhon constraint syntax (
banned_chr=[...], max_length=160) parsed into limitation fields - Goal types — Execute Command, Read File, Read Env Var (target field adapts)
- Execution context — exec, eval, or bare wrappers for encoding generators
- Generator log — per-generator status (ok/skipped/error) with category breakdown
- 9 technique transforms — applied centrally after chain resolution (TabReplace, ChrJoin, BracketEscape, DotEscape, Fullwidth, BoolArith, KwSplit, Base64, Hex)
- Dracula-themed UI — resizable panes, syntax-highlighted code editor, filterable results
bun install
bun run dev # dev server (port 5173)
bun run typecheck # TypeScript check
bun run lint # ESLint
bun run build # production build → docs/- IMPLEMENTATION.md — Full architecture, pipeline, technique reference (26+ techniques), gadget chain finder internals (multi-strategy solver, 180+ gadgets), CTF challenge index, Typhon input API, and developer guides
Inspired by Typhon Breaker, PyJailBreaker, and Parselmouth.
MIT © 2026 yuzu-octopus