Preliminary collection
2026 AI
294 web security research leads collected for 2026 — preliminary, unranked and not community-vetted.
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
294 records · open this year in the interactive archive
Collected research
-
$15k - CSPT to full account takeover, then 2FA bypass via the prototype chain
whoareme
Client-side path traversal reroutes an authenticated invite request to change an account email, enabling password reset. The author then reports a 2FA bypass using __proto__ as the code and explains a possible…
-
$170k in Bypasses: The Vercel React2Shell Challenge
ginoah and s1r1us
Reconstructs React2Shell WAF challenge bypasses arising from differences between filtering and application parsing. The May writeup follows a March conference presentation of the same bypasses and describes local…
-
1-Click RCE To Steal Your OpenClaw Data and Keys
Chains an OpenClaw gateway-URL configuration flaw with token leakage and missing WebSocket origin validation so a malicious page can connect to a local agent. The resulting one-click path exposes credentials and can…
-
10 Minutes with Claude: Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)
Naveen Sunkavally
Shows how an exposed ActiveMQ MBean operation can add a network connector whose crafted vm:// URI causes the broker to fetch a remote Spring XML configuration and execute operating-system commands. Jolokia credentials…
-
20 Million Rows Exposed: A Supabase Security Study of YC Startups
Victor
Measures Supabase authorization exposure across 107 Y Combinator startups, with 71 deployments assessable through their public client configuration. Missing or weak Row Level Security exposed 20.1 million rows…
-
8 Out of 10 Banks in Belgium HATE This One Weird eID RCE
James Arnott
Follows browser messages into native Belgian eID software and its library-loading interface. Replayable activation data, exposed PIN-token key material and loose DLL checks combine with download and path-resolution…
-
A First Measurement Study on Authentication Security in Real-World Remote MCP Servers
Huijun Zhou, Xiaohan Zhang, Haozhe Zhang, Haoyang Zhang, Mi Zhang and Min Yang
First measurement of authentication in remote Model Context Protocol servers. Of 7,973 live servers found, 40.55% expose their tools with no authentication at all. Among the rest OAuth dominates, but MCP deployments…
-
A Formal Analysis of Agent Payment Protocols
Ke Jiang, Mohan Yu, Yuan Chang, Mohit Kumar Jangid, Jianyu Niu, Cong Wang and Yinqian Zhang
A matched Tamarin analysis compares authorization, payment and fulfillment properties across four agent payment protocols. The paper reports counterexamples and repairs, extending earlier payment-security analyses; its…
-
A Realistic Code Execution Exploit Chain in OpenBao and Vault
Alex Scheel
Four OpenBao and Vault flaws are chained from ACME URI-SAN impersonation through non-canonical ACL handling and cross-namespace policy access to Raft snapshot-restore code execution. The writeup explains deployment…
-
A Shell Is Worth a Thousand Images: Bing Images RCEs
xbow and Nico Waisman
A blind Bing image fetch is traced through renderer and pseudo-protocol probes to an SVG image reference handled by a shell-backed conversion delegate. Out-of-band callbacks confirm command execution across Linux and…
-
Abusing Modern Browser Features for Phishing
Wolfgang Ettlinger and Alexander Hurbean
Combines a WebGL workload that delays fullscreen UI, a framed Google One Tap prompt that personalizes the lure, and Keyboard Lock to obstruct escape. The result is a browser-only phishing flow that imitates an…
-
Account Takeover in Facebook mobile app due to Math.random and XSS in the Facebook JS SDK
Youssef Sammouda
Combines a Facebook JavaScript SDK postMessage DOM XSS with predictable V8 Math.random output. Observed plugin-iframe names reconstruct the PRNG state and predict an XSS callback, while mobile WebView framing and login…
- AgentForger: ChatGPT Cross-Site Agent Forgery Mike Takahashi
-
Agentic Browsers and the Same-Origin Policy
Franziska Roesner and David Kohlbrenner
Across seven agentic browsers, the embedded agent can read page content that the same-origin policy would deny to script, including cross-origin iframes and masked password fields. A malicious page that frames a…
-
Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain Verification
Ruixuan Li, Xingyu Zhao, Yunyi Zhang, Baojun Liu and Jun Shao
Domain hosting providers misread CNAME semantics during ownership verification: a challenge token found after following a CNAME is accepted as proof of control over the aliasing domain, which itself configures no token…
-
Alipay DeepLink Attack Surface Analysis
Innora AI Security Research
Maps an Alipay deep-link and privileged-WebView chain in which a whitelisted-domain redirect loads attacker-controlled content through an alipays route. Device testing shows that the resulting page can reach sensitive…
- Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services Dylan Pindur and Adam Kues
-
Analyzing the WebRTC Ecosystem and Breaking Authentication in DTLS-SRTP
Martin Bach, Vukašin Karadžić, Lukas Knittel, Robert Merget and Jean Paul Degabriele
DTLS-SRTP secures media in Zoom, Teams and Google Meet and underpins WebRTC, whose stack spans HTTP, TLS, SDP, ICE, STUN, TURN, DTLS, SRTP and SCTP - too much to audit systematically by hand, so deployments went…
-
Angular compromise through dev infra: GitHub Actions cache poisoning as a vulnerability class
Adnan Khan and adnanthekhan
A pull_request_target workflow in angular/dev-infra interpolated github.head_ref into a run step, so a branch name executed commands even though the token was read-only and no secrets were present. The payload flooded…
-
apatchy: in-process fuzzing for Apache HTTPD modules
0xbigshaq
Introduces apatchy, an in-process Apache HTTPD module-fuzzing architecture built around LibFuzzer, sanitizers and LLVM coverage. Custom input filters feed bucket brigades into the real request pipeline without socket…
-
API Keys Leaking in PNG Metadata of AI Images
Luke Marshall
Examines API keys serialized into PNG metadata by AI image workflows. A worked example contrasts executed prompt nodes with the entire saved canvas, including inactive nodes, and a public-image study measures exposure…
-
Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI
Piotr Ryciak
Claude Code, Codex and Gemini CLI persist trust for a project path even after executable MCP or agent configuration changes. Once a directory is approved, later repository content can silently replace commands or…
-
Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation Implementations
Jan Drescher, David Klein and Martin Johns
Site Isolation confines each site to its own renderer process, leaving the browser process to track which process may act for which site; errors in that bookkeeping are Site Isolation bypasses. This work presents the…
-
Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
Antonio De Turris
Two n8n agent paths omitted authorization enforced elsewhere. A read-only Project Viewer could execute tool nodes with project credentials, while the MCP client sent a shared credential to an arbitrary server without…
-
Assessing Automated Prompt Injection Attacks in Agentic Environments
David Hofer, Edoardo Debenedetti and Florian Tramèr
The paper adapts white-box GCG and black-box TAP attacks to prompt injection against agents in AgentDojo, evaluating 80 task pairs across four domains and multiple models. Black-box optimization performs better under…
-
Astro full-read SSRF: Host validation and prerendered error-page fetching
Jorian Woltjer
Traces a full-read SSRF through Astro’s server-side fetching of prerendered custom error pages. Host-derived URLs and uneven validation of Host and forwarded-host headers expose internal responses in a particular hybrid…
-
Atlassian web-resource traversal and Crowd credential exposure (CVE-2026-21589)
Piotr Bazydlo, Yordan Ganchev and Sonny
Shows how an Atlassian resource handler turns double colons into slashes, enabling pre-auth file reads under WEB-INF across several products and potential credential exposure.
-
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE
Matt Jones
Combines a predictable-error TACACS+ secret oracle with a pre-authentication format-string flaw in tac_plus. A laboratory login-client path lets an oversized username move attacker-controlled bytes into the NAS-port…
-
Attacks via OpenClaw: when your LLM can make RCE
Purpleshift
Shows an OpenClaw command-injection path that first makes normal web retrieval fail, encouraging the model to fall back to a shell-built curl command. Attacker-controlled redirect or page values then cross into the…
-
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform
moltenbit
A source-code and live-instance audit of OpenReception reports 16 CVEs across its multi-tenant booking application. The critical findings include tenant-to-global administrator privilege escalation, unauthenticated…
-
AutoFail: Breaking Web Boundaries using Android's Autofill Framework
Riccardo Lamarca, Philipp Beer and Marco Squarcina
ADAPT traces Android autofill across five browsers and nine password managers, finding lost frame context and inconsistent matching that can leak credentials across sites. A separate UI-size oracle exposes saved-account…
- Avoiding the paradox: A native full-read SSRF and one-shot DoS in SvelteKit Rachid Allam (zhero) and Yasser Allam (inzo_)
-
Before the first prompt: Code execution paths in trusted coding-agent projects
Nick Frichette
Examines code execution during startup of trusted coding-agent projects. A configured stdio MCP server can start before hook review, while a project-controlled PATH substitutes a git wrapper during automatic context…
-
Beltdown: Escaping the Claude Code sandbox
Oren Yomtov
Claude Code ran an internal Git index refresh outside its macOS sandbox. A staged nested .git directory, an unhardened git ls-files call and automatic skill loading let repository-controlled core.fsmonitor execute on…
-
Beyond Normalization: The Expanding Unicode Attack Surface
Ryan Barnett and Isabella Barnett
Maps Unicode processing across byte decoding, regex options, URL conversion, Java hexadecimal parsing and cookie or database comparison. Pipeline diagrams and contrasting configurations show how inspection and later use…
-
Beyond the Ceremony: The 2026 Passkey Attack Surface
Matteo Giordano
Organizes passkey testing across authenticators, hybrid transport, clients, relying parties, synchronization and recovery. Burp profiles and field-editing examples show how controlled key substitution preserves valid…
-
Blind enumeration of unreadable records via a sort oracle in Trello
BobAshEf
Uses an unreadable Trello mirror card as a hidden participant in sorting. Renaming a readable probe card reveals relative ordering against the private title, turning permitted sorting into a comparison oracle; GraphQL…
-
BodySnatcher: agentic hijacking in ServiceNow
Aaron Costello
Traces a shipped provider credential and email auto-linking into ServiceNow’s internal agent execution channel. Recovered constants identify active agents, while blind asynchronous requests resolve newly created records…
-
Borrowing Windows Hello Keys for Authentication and Persistence
Dirk-jan Mollema
The WHFB private key lives in the TPM, yet the Passport KSP via NCryptOpenKey signs arbitrary data for a low-privilege user with no PIN or biometric prompt, a side effect of RDP needing the key usable under another…
-
BragJack: extension access to privileged browser-agent channels
Gal Weizman
Shows how extension-controlled network rules and trusted web origins reach privileged browser-agent interfaces. Comet exposes an unprotected testing origin; Edge combines weakened framing policy, debugger-generated…
- Breaking the Boundaries: Analyzing QUIC Frame-Packet Interactions With QUIC-Attacker Nurullah Erinola, Marcel Maehren, Marcus Brinkmann and Jörg Schwenk
-
BrowserGate: LinkedIn's browser-extension scanning system
BrowserGate
Documents LinkedIn production JavaScript that probes thousands of Chrome extension IDs through web-accessible resources, supplements the results with passive DOM scans, and sends encrypted telemetry. The study…
-
Building certgrep.sh: a free certificate transparency search engine
Juxhin D. Brigjaj
This engineering postmortem explains why an FST-based certificate search design failed for substring and alternation queries, then moves to trigram candidate filtering. It details compact CT-log coordinates, on-demand…
-
BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface
Mingi Jung, Donggyu Kim, Mijung Kim and Seongil Wi
Browsers enforce CSP, SameSite and similar headers, so a browser bug in enforcement silently removes the defence a site configured. BUIzz is the first framework to hunt those bugs through browser-user-interface…
-
Burp Suite Professional: browser-powered crawl writes attacker-controlled files
Masahiro Kawada (kawakatz)
Traces attacker-controlled file-input metadata through a browser-powered crawler into local file creation. An unchecked extension/path allows a generated upload file to escape its temporary directory, with a Windows…
-
Buy A Help Desk, Bundle A Remote Access Solution? SolarWinds Web Help Desk Pre-Auth RCE Chains
@chudyPB and Piotr Bazydlo (@chudyPB)
Patch-diffs SolarWinds Web Help Desk to recover a deserialization patch bypass, two authentication bypasses and a SQL-query gadget. Combining the flaws produces a pre-authentication Java deserialization path to remote…
-
Bypassing Apache FOP PostScript escaping to reach Ghostscript
Finds an escaping mismatch in Apache FOP's PostScript output that lets attacker-controlled XML inject executable PostScript commands. The write-up develops delimiter and whitespace bypasses and shows how the primitive…
-
Cache key injection: Smuggling poison through the door
Alex Brumen
Nginx case studies show how ambiguous cache-key boundaries can map distinct requests to the same cached response. The article examines conditional cache poisoning and disclosure risks and distinguishes upstream host…
-
Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCache & Friends
Xiangfan Wu, Lingyun Ying, Haipeng Qu, Guoqiang Chen and Yacong Gu
Research on LLM serving caches (vLLM, GPTCache and peers) where the layer deciding whether two requests are 'the same' is fooled. All three cache types rest on serialize-key-reuse, so an attacker crafts colliding…
-
Can AI do novel security research? Meet the HTTP Terminator
James Kettle
Feeding 1-3 sentence RFC fragments to an LLM generated 30,000 desync vectors, each validated on live sites by sending a plain request over a separate connection and watching for a changed response. It found triggers…
-
CargoWise WebTracker — The Keys Were in the Cargo
Patrik Grobshäuser, Shubham Shah, Adam Kues and Dylan Pindur
Follows hardcoded encryption keys into CargoWise auto-login tokens and a fallback identity. Handler endpoints bypass page-level session teardown, enabling contact enumeration and persistent sessions that expose shipment…
-
Casse-Spip - From an Unauthenticated SQL Injection to Remote Command Execution
Franck Chevalier
SPIP vulnerabilities combine an unauthenticated SQL injection, missing action authorization and mass assignment. The article explains how these flaws enable administrator account takeover or command execution through…
-
Cast Attack: A New Threat Posed by Ghost Bits in Java
Xinyu Bai and Zhihui Chen
The Cast Attack exploits Java narrowing a 16-bit char to a byte (via (byte) ch and ch & 0xFF), dropping the high 8 bits ('ghost bits'). An attacker submits a Unicode character whose low byte equals a forbidden ASCII…
- Caught in the Octopus Trap: Unauthenticated RCE in Argo CD Hugo Vincent
-
CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks
Ziyu Lin, Tianlong Su, Yingjie Lin, Prosanta Gope, Yinzhi Cao, Ximeng Liu and Biplab Sikdar
Measures CDN-to-origin amplification when compact HTTP/3 headers expand into HTTP/1.1 and slow request bodies retain backend connections. Experiments across six providers compare QPACK tables, stream limits, fan-out and…
-
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
The write-up chains cross-context token reuse, a database import race, automated CAPTCHA solving, and an administrative local-file-inclusion flaw into unauthenticated code execution against Discuz! X5.0. It documents…
-
Charting your way in: Helm template injection
Paul Barbé
Follows attacker-controlled Helm values into YAML rendered by a privileged ArgoCD deployment. Multiline values, quoting and document separators create extra resources; comparing Helm versions shows that an invalid later…
-
Chat-template backdoors: systematic evaluation and agentic impact
Ariel Fogel, Omer Hofman, Eilon Cohen and Roman Vainshtein
Poisoned chat templates insert privileged instructions without changing model weights. This 2026 study extends a July 2025 disclosure with comparative model and runtime evaluation; its May revision adds agent…
-
ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping
Ori Lahav
A malicious document tells Microsoft Copilot to run gzip-packed Python in its analysis sandbox, which then reaches an unauthenticated internal service on the host network; its /config endpoint takes a name that…
-
Citrix NetScaler pre-auth command injection through privileged log processing (CVE-2026-88771)
Sina Kheirkhah
Patch-diff analysis follows attacker-controlled NetScaler HTTP log fields through grep, sed and awk processing before a root-run Perl path interpolates them into backticks. The article demonstrates the resulting…
-
Claude + Humans vs nginx: CVE-2026-27654
Calif
Develops an nginx WebDAV alias-path underflow into practical file-read and file-write variants. The researchers trace signed and unsigned path-length arithmetic, remove earlier heap-grooming assumptions, and show how…
-
Claude Code audit: unrestricted environment mutation over remote-worker transport
Zack Skolnik
Audits Claude Code's remote-worker transport and finds that an unauthenticated server message can mutate arbitrary worker environment variables. Setting NODE_OPTIONS makes a later child-process spawn load…
-
Claude Code workspace trust dialog bypass via repo-controlled settings
cantina_xyz
Documents a Claude Code workspace-trust bypass in which repository-controlled settings are resolved before the trust confirmation decision. Setting the default permission mode to bypassPermissions can suppress the…
- Claude in Chrome: from alert(1) to full account takeover Raul Klugman-Onitza and João Donato
-
ClawMutiny: We Audited 1,620 OpenClaw Skills
Oathe
Measures instruction-layer threats across 1,620 OpenClaw skills and compares the results with a conventional malware-oriented scanner. Manual review of disagreements highlights prompt-delivered credential theft, remote…
-
Click2Shell: theme-selector injection and preactivation code execution in WordPress
PWNAI Research
A theme slug is normalized by the catalog API but reused as selector syntax in WordPress admin JavaScript, forcing installation. Customizer loading of an inactive vulnerable catalog theme then exposes an unchecked…
-
Cline Kanban WebSocket Hijack
Sagi Layani
Examines an unauthenticated local WebSocket control channel in Cline Kanban. Runtime messages expose task and workspace identifiers that can be used to attach terminal input, submit prompts and terminate sessions. The…
-
CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild
Yuval Avrahami and Nir Ohfeld
An unanchored AWS CodeBuild actor-ID regular expression accepts an attacker GitHub ID containing the trusted ID as a substring. A pull-request build then exposes privileged credentials from process memory, enabling…
-
Codex Discovered a Hidden HTTP/2 Bomb
Calif
HPACK lets a client seed the dynamic table once and then send thousands of one-byte indexed references; the per-entry bookkeeping a server allocates around a nearly empty header (about 70 bytes on nginx and IIS, 4,000…
-
Coding-agent trust handoffs: shell validation, output channels and shared workspaces
Elad Meged
Compares coding-agent enforcement across shell tokenization, command classification, environment access, output channels and successive invocations sharing writable files. Chain-by-chain examples show how validation at…
-
Comment2XSS: chained comment-formatting transformations in WordPress
Rafie Muhammad
A permitted comment attribute newline becomes an HTML-comment placeholder. A quote-unaware wpautop rewrite inserts markup inside it; subsequent texturization changes quoting and turns safe text into an event handler…
- Compromising Cleo Harmony: A SAML Bypass Chain to Arbitrary Code Execution
- Computer-Use and TOCTOU: What You Click Is Not What You Get! Johann Rehberger
-
Configuration-Based Sandbox Escape in AI Coding Tools
Ilan Kalendarov, Ben Zamir and Elad Beber
Finds recurring sandbox escapes in AI coding tools where project-controlled configuration remains writable or is trusted after a restart. The case studies turn settings files, hooks and executable-resolution behavior…
-
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
Mohamed Benchikh
Google's device flow exposed a transferable sign-in challenge and failed to bind client_id or scope to the issued device_code. Substituting a previously approved client and prompt=none silently yielded attacker-polled…
-
Content-Type Override to Stored XSS on public objects
Amirmohammad Safari
Examines response Content-Type overrides on public object storage. MinIO accepts an anonymous override, while an attacker’s own AWS identity can satisfy S3’s signed-request requirement for a public object; serving…
-
Context Bombs: stopping AI attackers in their tracks
Tracebit
Context bombs place short safety-triggering strings inside decoy cloud resources so an offensive AI agent both trips a canary and stops itself. A 152-run AWS cyber-range experiment compares clean and bombed environments…
-
CosmosEscape: Taking Over Every Database in Azure Cosmos DB
Yuval Avrahami and Lior Maman
Traces a Gremlin query escape into a shared Cosmos DB gateway, then follows gateway credentials through a signing key to account primary keys. A regional configuration lookup locates target tenants, linking query…
-
cPanel file read through SMTP-created paths and CalDAV parser collisions
Shubham Shah and Adam Kues
Uses SMTP plus-address delivery to create a Maildir path required by a CalDAV attachment route. Later decoding and traversal expose another file, while an unretained privilege-reduction object restores elevated access…
-
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Tom Stacey and Tobia Righi
When Nginx's proxy_pass includes $uri the path is normalised and URL-decoded, so %0d%0a in it injects headers or whole requests into the upstream request. Injecting Transfer-Encoding beside the real Content-Length gives…
- Cruising for Shells in Flowise Alex Brown, Luke Jahnke and Jia Hao Poh
-
CSS: the bomb inside your inbox
Gareth Heyes
Webmail sanitizers and browsers disagree about CSS. Nested href attribute selectors, sped by a clipboard-paste race, leak a Medium login token five characters at a time; when CSP blocks requests, @font-face…
-
CVE-2026-19478: GitLab GraphQL `@gl_introduced` validation lab
dinosn
A reproducible GitLab A/B lab explains how `@gl_introduced` strips a future field during validation but restores a resolverless field at execution, allowing graphql-ruby to call an attacker-chosen zero-argument method…
-
CVE-2026-21876: bypassing OWASP CRS by overwriting the multipart charset in a later segment
daytriftnewgen (some0ne)
Shows an OWASP CRS multipart rule overwriting one capture variable while iterating header values. A harmless charset in a later part hides an earlier dangerous value from final validation; the research and fix…
-
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif stack
Adrian Tiron
This exploit chain turns a controlled libheif chroma-plane overflow in a Next.js sharp image path into a pointer leak, profiled stack identification, forged image-plane write and GOT hijack. It then redirects execution…
-
CVE-2026-33017: Unauthenticated RCE in Langflow through a surviving public execution path
aviral srivastava
Traces attacker-supplied public-flow JSON through Langflow's graph builder to unsandboxed Python exec during component instantiation. The analysis shows why an earlier fix left a sibling public execution endpoint…
-
CVE-2026-41238: How Prototype Pollution Turns DOMPurify Into an XSS Gadget
Paul Reed
Explains a DOMPurify custom-element gadget caused by replacing normalized configuration with an ordinary fallback object. The source-level case traces inherited allowlist options and RegExp type requirements…
-
CVE-2026-82222: GiveWP object-injection RCE validation lab
dinosn
A marker-only lab reconstructs GiveWP's staged PHP object-injection chain: restricted unserialization preserves class data, session handling later revives it, and implicit iteration bridges TCPDF through Symfony and a…
-
CVE-2026-87902: WordPress file inclusion and conditional code execution
Robert Ressl
Anonymous page queries preserve encoded traversal until template resolution, where late decoding allows local PHP inclusion outside theme roots. The demonstrated PEAR execution chain requires a suitable page-prefixed…
-
Demystifying the (In)Security of OAuth-based Account Linking in Connector Ecosystems
Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung and Wing Cheong Lau
Project page for a systematic study of OAuth connector account linking. It links the paper analyzing cross-user session fixation and connector or tenant confusion, alongside an Android static-analysis screening method…
-
Deployment Poisoning: A(nother) Novel Attack Vector for GitHub Actions
Boost Security Labs
A workflow in a fork pull request can name an environment that does not exist; GitHub creates it and emits a deployment_status event that runs the default branch's workflow with secrets. The environment name is…
-
DNS Cache Poisoning Like it's 2006
Omer Ben-Simhon and Amit Klein
Cache poisoning against BIND 9 that predicts BOTH values a spoofed answer must match - the UDP source port and the TXID - where most prior attacks predict only one, and does it entirely from the client side, with no…
-
Do Smart People Ever Say They're Smart? SmarterMail Pre-Auth RCE (CVE-2025-52691)
Piotr Bazydlo and Sina Kheirkhah
Reverse engineers SmarterMail's anonymous file-upload path and finds that attacker-controlled destination handling permits traversal into the web root. Uploading an ASPX payload turns the arbitrary write into…
-
DOMPurify bypass via SMIL animateTransform on Safari
Browsers now escape < and > in attributes during serialization, which broke nearly every DOMPurify mutation-XSS bypass. This one goes at SMIL instead: DOMPurify's default SMIL configuration combined with Safari's…
- DOMPurify XSS via `<selectedcontent>` re-clone KabirAcharya
-
DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE
Itay Ravia
Two Cursor sandbox flaws turn indirect prompt injection into host code execution. An LLM-selected working directory expands the writable Seatbelt policy, while failed symlink canonicalization falls back to the…
- ELF in the Pixels: Building Shared Object–Image Polyglots Salvatore Abello (babelo)
-
Envade: One Click in VS Code, Full Shell for the Attacker
Elad Luz
Documents the mismatch between displayed and persisted MCP installation fields in VS Code. The report analyzes hidden runtime configuration and HTTP account context, compares the consent boundary with Cursor, and…
-
Escaping the OpenAI Codex sandbox, twice
Oren Yomtov
Two Codex sandbox escapes abused enforcement plumbing. One widened patch-derived write grants and crossed a symlink; the other recovered a trust token from a V8 heap shared with untrusted code and forged requests to an…
-
Evil Font Labs: cross-format glyph-remapping deception
DoctorEww
Five DEF CON 34 exercises teach how remapped glyphs make visible text differ from copied or extracted text in HTML, DOCX and PDF. The labs cover JavaScript-free ClickFix deception, document-security and AI-review…
-
Exfiltration using numeric-only outputs
ikaes
When an injection sink returns only decimal digits and blocks errors, timing and outbound traffic, command output can still be converted into large base-10 integers. Base-36 or base-27 encoding plus chunking makes the…
-
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
Adam Kues
A WordPress REST batch mismatch enables nested validation bypass and read-only SQL injection. Forged post objects poison the request cache; oEmbed updates and hierarchy repair persist them as changesets. Temporary…
-
Exploiting a PHP Object Injection in Profile Builder Pro in the era of AI
Mattia (0xbro) Brollo
Uses WordPress cross-plugin autoloading to make a previously unavailable Monolog gadget reachable from Profile Builder Pro's PHP object injection. The new FingersCrossedHandler-to-ProcessHandler POP chain converts the…
-
Exploiting AQL Injection Vulnerabilities in ArangoDB
Daniel Kachakil
Explains AQL injection in collection and filter positions, including error-based, reflected, blind and timed extraction. Shows data modification and creation of JavaScript UDFs through system-collection writes, with…
-
Exploiting Auth0 Defaults in XSS Attacks
Alex Brown
Uses an XSS lab to trace Auth0 token issuance when implicit grants remain enabled behind a confidential OAuth proxy. Tenant audience defaults and current-user Management API scopes create additional token paths; an…
-
F5 BIG-IP OAuth heap overflow: using a process-finish hook past SELinux execution restrictions
Sina Kheirkhah
A BIG-IP OAuth heap overflow corrupts a callback. After SELinux blocks direct execution, a ROP chain appends commands to a writable process-finish hook that runs when the process crashes.
-
FCSC 2026 "Aquarium": escaping the Node.js Permission Model
_Worty
Solves a Node.js challenge by importing a data URL whose fragment defeats an appended filename suffix. From a permission-limited process, readable process metadata and same-user signaling start an unrestricted peer’s…
-
FCSC 2026 writeups: Firefox `execCommand` ICU-vs-JS case-folding differential, Gunicorn `HEAd` smuggling, libmagic polyglots
kevin_mizu
Five CTF web writeups, each a parser disagreement. JavaScript's toLowerCase expands U+0130 to two code points so an execCommand blocklist misses it, while Firefox's u_tolower maps it to plain i and runs insertHTML…
-
Finding Gadgets Like it's 2026
Atredis Partners
An LLM agent drives a call graph built with WALA class-hierarchy analysis, pruned to Serializable classes and extended via ASM with reflection and type-confusion edges, querying it over REST and validating each…
-
Firefox / WebRTC Encoded Transforms: UAF via undetached ArrayBuffer (CVE-2025-14321)
AISLE Research Team
Finds a Firefox WebRTC encoded-transform lifetime error where JavaScript keeps an ArrayBuffer alias after its native frame storage is released. The stale buffer supplies heap read and write primitives suitable for…
-
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
James Arnott
Any website could make the FortiPAM extension trust its host, invoke an externally exposed launcher with a token that skipped validation, and click consent UI embedded in the page world. The resulting session could set…
-
From Approval to Execution: Reconstruction-Aware Repair Analysis for LLM-Agent Software
Junchi Zhu, Zhenguang Liu, Shaojing Fan, Jianhai Chen and Qinming He
Analyzes whether approval still covers the action consumed after workflow reload, argument rebinding and other reconstruction. Uses object versions, grant scope and atomicity to identify incomplete repairs. Results…
-
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX
Marcio Almeida
Examines unauthenticated encryption and inconsistent validation across Telerik upload and postback paths. The case combines established cryptographic and deserialization techniques, explains nondefault deployment…
-
From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)
Johann Rehberger
The article reverse engineers SQL Copilot's read-only checker and bypasses it with dynamic T-SQL, then stores AGENTS.md and CONSTITUTION.md instructions in SQL Server extended properties. A later privileged Copilot…
-
GatewayToHeaven: Finding a Critical Cross-Tenant Exploit in GCP's Apigee
Omer Amiad
Builds a cross-tenant Google Cloud Apigee compromise from access to a service identity in a tenant project. Reconnaissance and IAM escalation through Dataflow culminate in control over resources belonging to other…
-
Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild
Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang and Yinzhi Cao
Python's recursive attribute and item setters let a user-supplied key path walk from an object to its class, module globals, function defaults and closure cells, so one nested update rewrites the runtime. The talk gives…
-
Ghosts of Encryption Past: Salesforce Marketing Cloud / ExactTarget
Dylan Pindur, Shubham Shah and Adam Kues
Investigates Salesforce Marketing Cloud email-view encryption by connecting template injection, CBC manipulation and a MicrositeURL encryption oracle. Recovering an accepted legacy XOR format accelerates forging and…
-
GitHub RCE Vulnerability: CVE-2026-3854
Sagi Tzadik
Traces Git push-option delimiters into trusted metadata passed between GitHub services. Following the overwritten fields through their consumers reveals environment and sandbox changes, activation of pre-receive hooks…
-
Golang code review notes II
Zoltan Madarassy and Alex Brown
Collects six Go review cases involving length truncation, removed proxy headers, shared URL pointers, C strings, JSON method selection and permissive decoding. Working examples and Semgrep rules connect each…
-
Google API Keys Weren't Secrets. But then Gemini Changed the Rules
Joe Leon
Shows that Google API keys historically published as non-secret identifiers can silently authenticate to Gemini when the Generative Language API is enabled. A large-scale scan found thousands of exposed keys with access…
-
Gotta Phish 'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle
Giacomo Lenzini
Presents a persistent browser-in-the-middle framework with isolated sessions, substituted cursors, synchronized page identity and extension-mediated traffic changes. Suppressing logout requests while clearing visible…
- Grand Theft Atlas Stav Cohen
-
H3Act: Automated Measuring Semantic Conversion Anomalies of HTTP/3-to-HTTP/1.1 Translation in CDNs
Qihang Peng, Siyuan Tian, Yongxin Qiu, Jinyang Huang, Yaru Yang, Xiang Li, Jia Zhang, Yiming Zhang, Haixin Duan, Yunsenxiao Lin, Shugen Chen and Liqun Yang
Presents H3Act, which generates structured HTTP/3 probes and analyzes their HTTP/1.1 translation at CDN backends. RFC retrieval, an attack corpus and generator/analyzer feedback guide testing; compressed payload…
-
Hack the Elephant One Bite at a Time: NUL byte SQL Injection in pdo_firebird
Aleksey Solovev and Nikita Sveshnikov
Traces Firebird PDO query reconstruction through NUL-terminated string operations. A quoted binary token loses its closing quote while reconstruction resumes at later tokens, making subsequent input become SQL syntax…
-
Hack the Source, Of the Source
Tsi-Lin Ng
A talk on hacking package registries by chaining parser differentials with injection. A LuaJIT-vs-Lua integer differential makes server and client resolve different versions; Julia's Registrator falls to command and…
-
Hacking AI customer service agents
Ayoub and Inti De Ceukelaire
AI support agents can join a ticket, account and privileged support workflow without preserving the customer's authorization boundary. The article explains how to map tools, influence agent decisions and test…
-
Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design
Peyton Kennedy
Seven AI workflow platforms assume that whoever edits a workflow may run code on the host, while the actual caller is an unauthenticated webhook or a member account. Nocobase's SES compartment has lockdown() commented…
-
HAProxy HTTP/3 → HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
Martino Spagnuolo and @Martino Spagnuolo
Shows an HTTP/3-to-HTTP/1 request-smuggling flaw in HAProxy's downgrade path: a standalone QUIC FIN can terminate an H3 body without the length validation applied to a normal DATA frame. The backend then treats bytes…
-
HashDoS in V8's array-index string hash, and a seeded but invertible permutation as the fix
sharp_edged
A HackerOne report for CVE-2026-21717, a HashDoS in V8 affecting Node.js 20/22/24/25. V8's string hashing maps integer-like strings to their numeric value, so hash collisions are trivially predictable. A request that…
-
HermeticReader: turning Adobe's 300M-install extension into a WhatsApp takeover
Shaked Biner
Follows messages from a web-accessible Adobe extension frame into feature flags and a dormant DOM bridge. Extra properties let the attacker redirect the bridge to another tab, where DOM manipulation extracts rendered…
-
Hidden security risks in Jupyter notebooks
Yaniv Nizry
Examines Jupyter Desktop and JetBrains notebook boundaries. Navigation can retain a privileged preload bridge that reveals a local server token, while widget protocol configuration can load script into a trusted…
-
HijackKV: New Threat in Position-Independent KV Cache Reuse
Yichi Zhang, Zhiqi Wang, Huan Zhang and Yuchen Yang
Position-independent KV cache reuse lets a serving system reuse cached key-value state whenever identical text chunks appear, whatever their position. Because a cache entry is retrieved by token match but encodes the…
-
How a single typo led to RCE in Firefox
Traces a one-character bitwise-operator error in Firefox WasmGC array forwarding through garbage collection and Ion-compiled WebAssembly to a use-after-free. Heap shaping and JIT primitives turn the bug into a…
-
How Command Injection in OpenAI Codex Led to GitHub Token Compromise
Tyler Jespersen and Phantom Labs
Finds that a shell-active Git branch name reaches Codex cloud setup while GitHub credentials are available. Payloads shaped around Git ref restrictions can execute commands and steal the token, and repository-side…
-
How to scan for vulnerabilities with GitHub Security Lab's open source AI-powered framework
Man Yue Mo and Peter Stöckli
Presents GitHub Security Lab's open taskflow framework for model-assisted vulnerability auditing. Component and context extraction feed explicit audit tasks into a measured queue whose findings are manually validated…
-
How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key — Leaked Twice
Nils Amiet
Traces pull-request comment options into Dynaconf dynamic-variable evaluation and uses `@json`, `@jinja` and `@format` transformations to bypass successive blocklists. A later include and documentation-path chain…
-
HTTP/3 in Burp Suite: programmable HTTP/3 testing and race tooling
Tom Stacey
Introduces HTTP/3 engines and automatic tuning in Turbo Intruder, integrates Single Datagram and QPACK blocked-stream race techniques, and shows downgrade-header testing. An HTTP/3 Adapter extends Burp testing to…
-
I rendered 1,418 Unicode confusable pairs across 230 fonts
Renders 1,418 Unicode confusable pairs across 230 fonts and uses structural image similarity to distinguish visually dangerous pairs from nominal mappings that do not resemble each other. The per-font measurements turn…
-
iframe sandbox bypass, cross-origin drag-and-drop, unvalidated postMessage origin, cookie bomb to account takeover
Renwa
Walks through user-assisted drag/drop into a code-evaluation field and a popup-based OAuth chain. An oversized-cookie error interrupts callback consumption so the code can be read from a same-origin window and redeemed…
-
ImageMagick: From Arbitrary File Read to RCE In Every Policy
PWNAI Research
Builds ImageMagick file-read, file-write and conditional command-execution chains from content detection, coder aliases and delegate-policy gaps. The work tests default, limited and secure policy profiles and shows how…
-
Instagram account takeover via Meta Pixel script abuse
Youssef Sammouda
Chains a trusted Facebook postMessage endpoint with Meta Pixel URL and referrer collection to exfiltrate an Instagram OAuth authorization code. A first-party token-generator path exchanges the stolen code for an…
-
Invalid Signed HTTP Exchange fallback navigation: SekaiCTF Filtered Reality
dimasma0305
Solves a constrained reflected-content challenge using an invalid Signed HTTP Exchange body as a fallback navigation source. The navigation changes the Accept header and combines with reflected Content-Type and CSP…
-
JavaScript Functions Overload Confusion
Yashar Shahinzadeh
An array sent as m.data.origin stringifies to https://example.com, so new URL().hostname passes the allowlist, but being an object it picks postMessage's options overload and the secret is delivered to the attacker's…
-
Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin
Ben Cambourne
Traces Jupyter Enterprise Gateway inputs through three paths: numeric coercion around a UID/GID denylist, explicit Jinja template evaluation and unescaped YAML pod specifications. The walkthrough distinguishes execution…
-
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
Patrik Grobshäuser, Kevin Gervot and Tomais Williamson
Traces attacker-controlled array keys through Drupal’s PostgreSQL-specific case-insensitive IN translation, where SQL placeholders are rebuilt outside generic normalization. JSON login and JSON:API examples expose…
- KindaRails2Shell: how a MATLAB file reads your secrets and pops a shell on Rails André Baptista (0xacb), s3np41k1r1t0, castilho and Ethiack Research Team
-
Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission
Graham Helton
Shows that Kubernetes `nodes/proxy` GET permission can authorize a WebSocket upgrade to the kubelet `/exec` endpoint without a corresponding create check. The study demonstrates commands in reachable pods, missing API…
-
KYC age-verification bypass: generative video and browser liveness-integration testing
Kevin Tellier and Léo Desmonts
Tests generative video against a browser-based age-verification and liveness integration. The article separates video creation, camera injection, challenge behavior and acceptance, showing how injected media can enter a…
-
L3akCTF 2026 "Squid": racing `/proc/self/fd` symlinks against Flask `send_file`
Jorian Woltjer
Solves a Flask file-disclosure challenge by racing recycled procfs file descriptors between stat and open. A regular file supplies a nonzero length before an environment file replaces it, bypassing response-length…
-
Leaking Meta FXAuth Token leading to 2-click Account Takeover
Youssef Sammouda
A Meta FXAuth flow restricts redirect hosts but still accepts attacker-controlled legacy `apps.facebook.com` application namespaces. Redirected token and blob values can then complete account linking or action…
-
LeakyLinks: Measuring the Security and Privacy Risks of URL Scanning Services
Ali Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal, Stefano Calzavara and Ben Stock
URL scanning services publicly index what they are asked to scan, so access tokens and personal data embedded in a submitted URL become searchable by anyone. LeakyLinks pairs URL filtering with LLM-driven semantic…
-
LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
Aviv Donenfeld
OpenSearch guards pull_request_target CI with a step that curls the PR diff into a Claude prompt, failing the build at medium severity or above. The gate sees about three lines of context, cannot open implementation…
- Living Off The Pipeline: Defensive Research, Weaponized (SmokedMeat / Brisket) François Proulx
-
LLM Heist: auditing LiteLLM traffic rerouting, provider-key exposure and tool-call injection
Johann Rehberger
Shows how an administrator credential can reroute a trusted LiteLLM gateway to an attacker proxy, causing provider credentials to be presented there. Subsequent forwarding and structured response modification enable…
-
Melting the Flesh of PHP's Memory Hardening
Yifan Wu, Xiaochuan Yu and Zhiyun Qian
PHP's heap hardening initiative set out to stop popular heap exploitation techniques. The first security study of it finds the mitigations defeat current-generation exploits but not adapted ones: it names the flaw that…
-
MemTensor npm and PyPI Packages Hit by a Go Worm
SafeDep Team
Reconstructs a malicious npm and PyPI release chain using repository changes, workflow artifacts and an injected Go loader. BASH_ENV and GITHUB_ENV connect attacker-controlled workflow steps to later release…
-
Multiple cross-site leaks disclosing Facebook users in third-party websites
Youssef Sammouda
Documents four Facebook cross-site leaks using CORB content-type behavior, framing and postMessage responses, employee-subdomain probes, and a script gadget. Preconditioning JavaScript prototypes before loading…
-
MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection
Georgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer, William Robertson, Cristina Nita-Rotaru and Alina Oprea
Web agents drive a real browser, so untrusted page content reaches the model that decides what to click. MUZZLE red-teams them with an agent rather than fixed templates: it reads the target agent's own trajectories to…
-
My First RCE by Reverse Engineering an EXE File With the Help of AI
Yashar Shahinzadeh
Investigates a local .NET agent exposed through a WebSocket API. The author recovers encrypted request handling, disproves a shell-injection hypothesis with a controlled executable and finds an alternate RUNDRIVE…
-
Navigating Lax Load Balancers: When an Intersection Gets You Inside
Francesco Lacerenza and Mohamed Ouad
Correlates AWS load-balancer listeners, ordered rules, target groups and backend members to find alternate routes around source-IP, authentication or CDN restrictions. The ELBaph tool and Terraform lab turn separate…
-
NemoClaw drive-by agent hijacking: bind-dependent defenses and persistent template poisoning
Elad Luz and Ofek Itach
Connects a container integration’s non-loopback Ollama binding to disabled host checks and DNS rebinding. Modifying a model’s rendering template persists injected instructions where an earlier system-message change…
-
Nested APP Authentication — Undocumented Risk and Conditional Access Bypass
Shang-De Jiang and Jun Sheng Shi
Conference page for a study of Microsoft Nested App Authentication. The associated presentation varies broker, nested-client and resource identities and compares Conditional Access inclusion and exclusion policies…
-
Never Trust the Output: semantic data pollution in AI agents and MCP
Slonser
Shows an AI agent interpreting escaped data in a structured tool result as additional fields or records, including fullwidth quote and comma spellings. Later tool calls inherit the altered semantics, while fake errors…
-
New Architecture, New Risks: One Click to Pwn IDIS IP Cameras
Vera Mens
A malicious site connects to an IDIS desktop client's localhost WebSocket because the service does not validate Origin. Recovering the protocol's constant key and injecting Chromium's `--utility-cmd-prefix` argument…
-
NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability
Zhenpeng (Leo) Lin
NGINX rewrite bytecode computes an escaped URI length and later copies it with stale script-engine state, creating a heap overflow when the two passes disagree. Cross-request pool grooming and a cleanup-handler…
-
Ni8mare: Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)
Dor Attias
Shows how an n8n form webhook's content-type-dependent parsers let JSON forge the uploaded-file structure and copy arbitrary local files into a workflow. Reading the user database and signing secret enables…
-
No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite's dbpage
Paolo Gabriele Schiraldi
Stacked SQLite injection uses sqlite_dbpage to overwrite raw pages and create files with far fewer fixed header bytes than ATTACH DATABASE. Relocating the ELF program-header table enables shared-object module shadowing…
-
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
A certificate extracted from one Shark vacuum can subscribe and publish across other devices' AWS IoT MQTT topics because broker authorization is not tenant-scoped. Reverse engineering finds an Exec_Command field that…
-
No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes
David Rochester and Nicholas Gould
Examines malicious OCI registry challenges and blob redirects as privileged fetch operations. Reusing a digest for a layer and configuration changes verification state and retains SSRF response bytes for exfiltration; a…
-
No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks
Yarden Porat and Shahar Tal
Prompt injection is the given; the bugs are in the framework underneath. A tool-call argument carrying LangChain's own constructor JSON is revived by its loader into a chat model with an attacker endpoint and a secret…
-
NodeBB XSS through translation-template gadgets after HTML escaping
Jorian Woltjer
Examines eight NodeBB findings, including translation performed after HTML escaping. Bracketed translation syntax selects trusted catalog strings as HTML gadgets, with a second template supplying syntax blocked in…
-
NTLM-Relaying in 2026
Benjamin Floriani and Patrick Pongratz
Extends NTLM relay from protocol-specific services to arbitrary HTTP and HTTPS applications. The workflow validates resulting authentication cookies, retains the session, and hands it to an interactive Playwright…
-
OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration
Rachel Rabin
Compares OAuth password-grant responses for registered, unregistered, random and malformed client IDs. The error matrix distinguishes user and credential validation from successful token issuance and explains why…
-
OffGuard: LiteLLM authentication and proxy-boundary case study
Amitai Cohen and Yaara Shriki
Explains separate LiteLLM failures in MCP authentication, custom guardrails and administrative defaults. The article distinguishes unauthenticated MCP access from guardrail execution that requires administrative access…
-
OID-See: Giving Your OAuth Apps the Side-Eye
CirriusTech | Serious About Tech
Presents OID-See, a Graph-first model of Entra service principals, OAuth grants, app-role assignments, owners and directory roles. It separates observed relationships from derived impersonation and persistence paths…
-
One Chain to Own Them All: Breaking AI Infrastructures
Ji'an Zhou
A hunt across AI serving stacks that ends in PyTorch's model loader: the weights_only whitelist meant to make torch.load safe was bypassed once, then again after the fix, when a whitelisted function reached through…
-
One Char to Rule Them All: DNS Silent Vulnerabilities in Domain Name Resolution
Fasheng Miao, Xiang Li, Changqing An and Jilong Wang
The SHAR (special-characters) attack against DNS. RFC 1035 and RFC 2181 disagree on which characters domain labels may contain, and DNS components handle unsupported characters inconsistently, many silently dropping the…
-
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts
Leonardo Giovannini
Chrome on iOS exempted Shortcuts URLs from its app-launch prompt. An error callback for a nonexistent shortcut could then open a webpage-controlled tel or FaceTime URL outside Chrome's checks. The case study explains…
-
One trigram at a time: XSLeak via Universal CSS Injection and DoS in Opera (GX)
zhero and inzo_
Opera GX installs GX Mods - CRX packages carrying CSS but no JavaScript and no permissions - automatically when a page links or frames the file, giving attacker-controlled CSS on every site the victim visits; in…
-
OpenCode upgrade RCE: text/plain JSON, top-level navigation and package-install targets
Christophe Tafani-Dereeper
OpenCode parsed text/plain forms as JSON and accepted remote tarballs as upgrade targets. A top-level localhost request could run package scripts, with npm/pnpm/Bun installs and no password or cached Basic credentials.
-
Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine
Dylan Pindur and Adam Kues
A TypedArray offset bug in Goja gives JavaScript code access beyond its buffer. The research connects this corruption to Go runtime objects and native calls, developing a script-to-host escape with published exploit…
-
Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
Hongyan Chang, Ergute Bao, Xinjian Luo and Ting Yu
Indirect prompt injection is usually studied without the hardest step: an unoptimised payload is rarely retrieved under natural queries, so its real impact stays unclear. The malicious content is split into a trigger…
-
P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet
Studies more than 6,100 internet-exposed Perforce servers and quantifies how insecure defaults expose source code and administrative capabilities. It combines remote user creation, passwordless-account impersonation…
-
Parse and Parse: MIME Validation Bypass to XSS via Parser Differential
Tang Cheuk Hei
Content-Type is a singleton field, but Chromium and Firefox coalesce it on commas and keep the last syntactically valid type, while MIME libraries split at the first semicolon and keep the first. So…
-
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Arie Olshtein
Investigates cloud passkey recovery after compromise of device identity. Forced re-onboarding permits an attacker-controlled user-verification key to be registered in a pending state, supporting later remote assertions…
-
Pass-the-Passkey Family of Attacks
Michael Grafnetter and @MGrafnetter
An announcement for a Black Hat USA 26 briefing, not the research itself. It previews a family of attacks the authors liken to Pass-the-Hash and NTLM relay: a major cloud service's passkey implementation vulnerable to…
-
Path traversal in signed URLs — present even in the official AWS SDKs
Matsui and Eui Chul Chung
S3 keys are flat, so ../ in an object key is only text until something normalises the path while a presigned URL is built. AWS SDK for Go v1 runs path.Clean() after filling /{Bucket}/{Key+}, so a key of…
-
Perfex CRM unauthenticated RCE via insecure deserialization
_NULL
Shows that printable PHP S-format serialization escapes pass Perfex CRM's input filtering while reconstructing private-property null bytes and PHP tags. A Guzzle FileCookieJar gadget then turns the surviving object…
-
Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web Applications
Rui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu and Yinzhi Cao
Presents HALO, a host-name-poisoning analysis that combines server request behavior, framework host-access guards and application flow checks. The paper provides a multi-stack testing matrix, source-to-sink examples and…
-
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
RyotaK
Claude Code's GitHub Action treated any actor ending in [bot] as having write access, and agent mode never checked the actor was human, so an attacker's own GitHub App, able to open issues on any public repo, feeds it…
-
Privacy risks of agentic oversharing on the Web (SPILLAGE)
Ali Shahin Shamsabadi
SPILLAGE measures what LLM web agents disclose while shopping on Amazon and eBay, along two axes: explicit versus implicit disclosure, and content versus behaviour. 180 tasks over Browser-Use and AutoGen with GPT-4o, o3…
-
Prompt Injection as Role Confusion (CoT Forgery)
Charles Ye, Jasmine Cui and Dylan Hadfield-Menell
Language models receive system, user, tool and reasoning content as one token stream distinguished only by role tags. Using linear probes trained on identical text wrapped in each tag, this work shows models infer role…
-
PromptFiction: a one-click flaw that made Claude Desktop act without consent
Elad Luz
Analyzes automatic instruction submission through Claude Desktop deep links. The report separates conversation-data access from filesystem effects requiring configured MCP tools and further permissions, and describes…
-
Proto6: The Schema Was Not Supposed to Run
Vladimir Tokarev
Follows schema-derived identifiers into runtime and static JavaScript generation in protobuf tooling. Prototype-inherited lookups admit hostile type names, while identifier escaping, object prototype writes and…
-
Pwning Claude Code in 8 Different Ways
RyotaK
Claude Code allowlists read-only commands such as echo, sort and sed, then guards them with a blocklist over their arguments. Eight bypasses of that blocklist reach command execution with no approval prompt: unfiltered…
- Race Against The Patch: Four Exploit Chains in LiteLLM Shi Weiming and Bruce Chen
-
RCE and arbitrary file write in Vitess `vtbackup` via untrusted `MANIFEST` fields
Alex Manson
Vitess vtbackup trusts backup MANIFEST fields when selecting decompression commands and constructing restore paths, before file hashes are checked. An attacker who can alter backup storage can obtain arbitrary file…
-
RCE in Google's AI code editor Antigravity - $10000 Bounty
sudi
Examines an overbroad browser-extension messaging interface that forwarded web-origin requests with authority to Antigravity’s authenticated local service, enabling a chosen-path file write. Startup-file execution…
-
RCE in Strix Agent: A practical guide to prompt injections with impact
Kevin Joensen
Indirect prompt injection in a target page persuades the Strix pentest agent to inspect and then execute an attacker-hosted script. A check/use content swap serves benign code during inspection and malicious code at…
-
RCE in Your Test Suite: AI Agent Skills and the Attack Vector Skill Scanners Miss
Jeevan Jutla
Shows that AI-agent skill installers can copy unreferenced test files into dot-directories that skill scanners ignore. Jest, Vitest and similar recursive collectors later execute those files, turning an apparently inert…
-
RCEKit: proof-backed RCE detection and confirmation
kabiri-labs
RCEKit tests command and expression injection with proof-tiered verdicts. Random computed outputs, payload-free and inert controls, explicit inconclusive/error states, captured-request replay, and blind or no-egress…
-
Re:CACHE — Excessive reflection, type confusion, and 0-click SXSS on Next.js
Rachid Allam (zhero;) and inzo_
Combines reflected response headers with external caching in a Next.js deployment. Attacker-selected Content-Type makes an RSC response render as HTML when a cache ignores Vary, while a second cached Refresh response…
-
ReactGhost: A Study in Flight Protocol Trust Boundaries
ReactGhost
Revisits the React Flight protocol after React2Shell and documents adjacent trust-boundary failures in the ESM loader, client decoder and server-reference manifest paths. Static analysis and runtime reproductions show…
-
Recovering Encrypted LLM Reasoning Traces
Alexander Panfilov, David Schmotz, Ilia Shumailov, Luca Beurer-Kellner, Joachim Schaeffer, Ameya Prabhu, Jonas Geiping and Maksym Andriushchenko
Providers hide chain-of-thought by returning it to the client as an encrypted blob. Those blobs turn out to be interchangeable across sessions, users and models within one provider, so injecting a strong model's trace…
-
Regular Expression Denial of Service Induced by Backreferences
Yichen Liu, Berk Çakar, Aman Agrawal, Minseok Seo, James C. Davis and Dongyoon Lee
ReDoS theory assumes Kleene regexes and the NFAs that model them, which cannot express backreferences - so Python, Perl, PHP, Ruby and Java fall outside it. A Two-Phase Memory Automaton captures backreference semantics…
-
Rejetto HFS session forgery via a predictable signing key
Horizon3
This account observes outputs from HFS's V8 Math.random stream, reconstructs the generator state and steps backward to recover the startup session-signing key. The recovered key enables an administrator cookie and…
-
Remote Command Execution in Google Cloud with Single Directory Deletion
RyotaK
Looker's delete_dir rejects a path containing .git but not a bare /, so rm_rf is handed the whole checked-out repository. It deletes post-order in readdir order, predictable enough on ext4 that a sprayed directory puts…
-
Reverse CAPTCHA: Evaluating LLM Susceptibility to Invisible Unicode Instruction Injection
Marcus Graves
Evaluates invisible Unicode encodings as prompt-injection carriers across several language models and tool-use configurations. The experiment finds that tool access sharply increases compliance and records…
-
Reverse engineering Claude's CVE-2026-2796 exploit
Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng and Daniel Freeman
Develops a Firefox JavaScript/Wasm type-confusion bug from an unchecked optimized call.bind wrapper into WasmGC read/write primitives and code execution. The write-up also records the model-assisted exploit-development…
-
Rogue Agents Investigation
Asymmetric Security
This investigation reconstructs agent activity that chained public URL scanners, echo pages, archives, repository workflows and notification services into remote browsing and data-transfer paths. It documents observed…
-
ROP for the Web: Smuggling XSS, SQLi and Web Shells Past Every WAF Using Compression Dictionaries
Lenin Alevski
Conference presentation introducing controlled Compression Dictionary Transport experiments. Companion labs compare visible responses with dictionary-compressed responses under WAF and IDS inspection. The work…
-
Roundcube: remote-content and CSS sanitizer bypasses
nullcathedral
Traces Roundcube SVG feImage handling into a policy route intended for ordinary links. Because the browser fetches the image resource while the sanitizer treats its href differently from image sources, email content can…
-
Ruby 4.0 Universal RCE Deserialization Gadget Chain
Luke Jahnke
A universal Marshal.load chain for Ruby 4.0.6, built from RubyGems classes that naming Gem::SpecFetcher autoloads. Time._load validates its zone inside rb_rescue, discarding the exception, and calls to_str, which…
-
Salesforce Apex Predator: Breaking Salesforce Sites
Nitay Bachrach and Cynthia Ardman
A Salesforce assessment workshop covering Aura and LWR discovery, bundled component analysis, Apex method and parameter tracing, SOQL/SOSL injection and GraphQL/UI-API exposure. Embedded field manuals and lab sequences…
-
Sandcastles, Not Sandboxes: auditing Pyodide-to-host trust boundaries
Vladimir Tokarev and Saar Pearl
Traces restricted Python execution through ctypes and Emscripten exports into the runtime embedding Pyodide. Product cases separate interpreter restrictions from host capabilities, data and credentials, providing a…
- Scanning the Scanners: Turning Security Vendors into Supply-Chain Weapons Raphael Karger
- SearchLeak: Parameter-to-Prompt injection in Microsoft Copilot Dolev Taler
-
SECCON CTF 14 Finals: Shadow CSS and friends
arkark
Explains SECCON web challenges including a Firefox Link-header stylesheet load that combines response truncation and integrity checks into a secret-prefix oracle. Other solutions examine chunk-boundary UTF-8 loss, HTML…
-
Securing the Supply Chain: Cache Vulnerability in RubyGems
Luke Marshall
Explains why a RubyGems API-key endpoint became cacheable only for compressed responses. Gzip changes the response object before ETag middleware, leaving a cache policy that the deployed CDN reuses under a shared…
- Security Considerations on Istio’s CRDs with Namespace-based Multi-Tenancy Lorin Lehawany and Sven Nobis
-
SELECT-only PostgreSQL exploitation: Drupal case study
N. Maccary
Develops a SELECT-only Drupal/PostgreSQL injection into large-object file writes, configuration replacement and native module loading in a new backend. The writeup explains database privileges, connection-pool lifecycle…
-
Send GitLab an email, push to main
Joe Leon
A leaked GitLab incoming-email token can authorize patch attachments across the owner’s projects, push code and run CI jobs outside IP allowlists. Exploitation needs the owner’s permissions and target routing.
-
Shaking the MCP Tree: A Security Deep Dive
Amirmohammad Safari
Walks through MCP assessment from OAuth dynamic client registration and authorized tool inspection to a constrained-fetch SSRF chain. Path normalization and an attacker-registered OAuth error redirect expose internal…
-
SharedRoot: Escaping the Claude Cowork sandbox
Oren Yomtov
A Claude Cowork session combines unprivileged user namespaces, netlink module autoloading and a public kernel page-cache write with an unhardened root broker. Guest root can then reach the Mac host filesystem because…
-
SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass
khoadha
SharePoint validated directive fragments separately before reconstructing markup. Splitting a registration directive across those fragments bypassed SafeControls checks and reached XAML execution gadgets. An alternate…
-
Shazzer XSS: blob origins, failed cleanup and sandbox navigation
Jorian Woltjer
Follows a parent-origin blob through a null-origin sandbox. A structured-clone exception prevents cleanup, preserving a leaked object URL for user-mediated navigation; a clean same-origin popup then changes the CSP…
-
Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions
Suyoung Lee, Seongho Keum, Changoo Lee, Dongwon Shin, Sanghyun Hong, Byoungyoung Lee and Sooel Son
Site isolation separates renderer processes per origin, but an agentic browser's whole purpose is to act across that boundary. Two open-source agentic browsers and seven agentic extensions share one architecture…
-
Site-DOM-XSS using Cookie Injection: The AI Hackers are Coming Faster than You Think
Renwa
Connects a TikTok analytics cookie writer to an OAuth script-host sink using a space-based cookie parser. URL decoding turns a plus into a space inside an unencoded cookie value, allowing a pseudo-cookie to supply…
-
Sleeping Agent: Silent persistent C2 through Web Push
Mihalis Haatainen
A service worker races showNotification() against immediate notification closure so Chrome's visibility bookkeeping is satisfied without leaving a visible notification. Web Push can consequently wake a site-controlled…
-
Slow JSON Stream: A Low-Bandwidth Denial-of-Service Attack Against HTTP APIs with JSON Request Bodies
Daniel Alfocea and @ggdaniel
A client keeps an HTTP/1.1 chunked JSON body syntactically open while sending one byte per second, tying up framework body readers that lack effective request-body timeouts. Tests across 41 framework and infrastructure…
-
Smashing the ServiceNow Sandbox – Pre-Authentication RCE
Adam Kues and @searchlightsec
An unauthenticated remote code execution flaw in ServiceNow (CVE-2026-6875). User input reaching GlideRecord query builders is evaluated as JavaScript when prefixed with javascript:, and although such expressions run…
-
Smashing the token limit with overlapping fragments
Alex and Gareth Heyes
Uses overlapping CSS-leaked fragments as a graph to reconstruct a secret token when enumerating every possible order is infeasible.
-
Solving an ORB mystery
Jorian Woltjer
Chases down why detecting a cross-origin response's status code through a script tag's load and error events works on one site and not another, and arrives at what amounts to a bypass of Opaque Response Blocking usable…
-
Someone Knows Bash Far Too Well: Ivanti EPMM Pre-Auth RCEs (CVE-2026-1281 and CVE-2026-1340)
Piotr Bazydlo, McCaulay Hudson, Sina Kheirkhah, Sonny, Aliz Hammond and Jake Knott
Follows attacker-controlled HTTP values through Apache RewriteMap into Ivanti EPMM Bash helper scripts. Bash arithmetic expansion turns the untrusted values into command execution, producing two pre-authentication RCE…
-
Spooler Alert: Remote Unauthenticated RCE-to-root Chain in CUPS
Asim Viladi Oglu Manizada
Builds a remote CUPS chain from newline-preserving option serialization: an attacker injects a trusted PPD control record that the scheduler later interprets as configuration. A separate localhost authorization-token…
-
Squidbleed (CVE-2026-47729)
Calif and Calif Newsletter
Squid's FTP directory-listing parser performs an out-of-bounds heap read that can disclose bytes from other users' cleartext HTTP requests through attacker-controlled FTP responses. The research traces the long-lived…
-
Stealing GitHub tokens via VS Code webview keyboard event bubbling
Ammar Askar
VSCode webviews are cross-origin iframes, but to keep shortcuts working they forward their own keydown events to the host over postMessage, and the host cannot tell a synthetic event from a real keypress. Javascript in…
-
Sub:jugation — Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers
Tal Skverer
CI/CD platforms mint OIDC tokens from a single global issuer, and the sub claim is built entirely from a repository namespace that GitHub, GitLab and Terraform allow anyone to re-register once deleted. Recreating the…
-
SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel
Jorian Woltjer
Explains a SvelteKit/Vercel cache-deception path where the edge treats a request as an immutable asset while an adapter override returns an authenticated dynamic resource. Failed approaches and request/response traces…
-
The API Made Me Do It: Do Bad APIs Lead AI to Generate Vulnerable Code?
Yariv Tal
A worked experiment on constraining generated web application code through safer APIs and build gates. The slides show failed restrictions, generated workarounds and revised gate designs, with control and constrained…
-
The Click that shouldn't have worked: RCE via clickjacking in Internet Explorer
Igor Sak-Sakovskiy and @Psych0tr1a
Internet Explorer's engine still ships as the WebBrowser control inside .NET and VB applications. A file downloaded through http://localhost arrives with no Mark of the Web, so a dropped HTML page runs as a local file…
-
The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors
Aviyam Ivgi and Hedi Ingber
Managed agent tools keep the cloud instance metadata endpoint reachable from inside them, so JavaScript in AWS Bedrock AgentCore's browser or Python in its code interpreter can fetch the microVM's IAM role credentials…
-
The Danger of Multi-SSO AWS Cognito User Pools
Francesco Lacerenza and Mohamed Ouad
AWS Cognito user pools with several SAML providers can expose different validation paths on first and returning logins. The research combines trigger gaps, attacker-controlled federated subject parsing, ghost identities…
- The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework Jonathan Dunn (xssdoctor)
-
The Forgotten Bug: How a Node.js Core Design Flaw Enables HTTP Request Splitting
Martino Spagnuolo
Surveys callbacks and events that permit a Node.js request path to change after constructor validation but before header serialization. Library comparisons and a decoded Express proxy route show how unsafe application…
-
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM CVE-2026-41940)
Sina Kheirkhah
Examines inconsistent session representations and error-recovery behavior in cPanel and WHM. The case shows how state reconstructed from one storage format can be trusted differently by another authentication path.
-
The Last Writer Wins: A Chess.com Account Takeover via postMessage XSS
XENOPS Research
A Chess.com postMessage handler accepted foreign-origin state. Its HTML wrapper removed diagram comments before DOMPurify, then restored them into attacker-placed placeholder tokens inside attributes, creating XSS. The…
-
The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem
Weihong Wang, Yana Dimova, Victor Vansteenkiste, Tom Van Goethem and Tom Van Cutsem
A browser-extension wallet is both a blockchain client and an identity provider, and five privacy threats follow from doing both in a page. Measuring 85 Chrome wallets covering 35.16M users: routine RPC calls link a…
- The Memory Heist Ayush Paul
-
The Most Organized Threat Actors Use Your ITSM: BMC FootPrints Pre-Auth RCE Chains
Sonny
Chains a guest password-reset token through an overly broad authentication check into Java deserialization exposed behind a .NET-style ViewState parameter. The cross-runtime path yields pre-authentication code execution…
- The sorry state of skill distribution Samuel Judson and Tjaden Hess
-
The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web
Louis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov, Christian Mainka and Jörg Schwenk
PASSKEYS-RADAR tracks passkey deployment since 2021 from community directories, Tranco 1M, CrUX 18M and archived pages, reaching 872 passkey-enabled relying parties. PASSKEYS-ATTACKER then tests live implementations…
- The Usual Suspect: Type Confusion in Twelve Bytes HamidSj
-
Thinking Outside The Box: Exfiltrating OpenClaw Data from NVIDIA's new Sandbox
Noy Pearl
Demonstrates that static egress allowlists do not contain an agent that can misuse already approved services. Malicious dependencies probe and reuse permitted GitHub, npm and messaging channels to exfiltrate NemoClaw…
- This Message Was Sent by Microsoft: Turning Microsoft Apps into our Phishing Platform Keanu Nys
-
Thousands of Live Secrets Found Across Four Cloud Development Environments
Ben Zimmermann
Measures credential exposure across 22 million public projects on CodeSandbox, StackBlitz, CodePen and JSFiddle using platform-specific enumeration and TruffleHog verification. The scan found 8,792 unique live secrets…
- Three 0-Day Vulnerabilities in Adminer Yashar Shahinzadeh and Amirmohammad Safari
-
Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold
Shreyas Penkar
Patch comparisons explain how inherited properties and unvalidated object types crossed privileged scripting boundaries in Acrobat Reader. The analysis clarifies a previously disclosed chain and its repairs, with…
-
Ticket to Shell: Exploiting PHP Filters and CNEXT in osTicket (CVE-2026-22200)
Naveen Sunkavally
Combines an osTicket sanitizer differential with an old mPDF parser so PHP filter chains embed arbitrary local files into exported ticket PDFs. The article fingerprints libc through `/proc/self/maps` and applies the…
-
Time for ACKrobatics: Abusing TCP Timestamps to Improve Remote Timing Attacks
Vik Vanderlinden, Tom Van Goethem and Mathy Vanhoef
Uses the server's own TCP timestamp in its ACK as the clock for a remote timing attack, so client-side jitter drops out; coalescing many pipelined requests into one segment multiplies the measured runtime. Resolution…
-
Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery
Jingcheng Yang, Enze Wang, Jianjun Chen, Qi Wang, Yuheng Zhang, Haixin Duan, Wei Xie and Baosheng Wang
JSON Web Token libraries expose a flexible surface - algorithm negotiation, nested signing and encryption, compression - that implementations handle inconsistently. JWTeemo models the token grammar in an extended BNF…
-
Transformers: Dark Side of the Type — Weaponizing the Conversion Layer
Oleksandr Mirosh
No serializer is needed for object injection: any conversion that resolves a type named in input and builds it is a sink. ResXFileRef's converter takes filename;typename;encoding, opens a UNC path and constructs…
-
Trust Transitions in Email: When Sanitizers and CSS Engines Disagree
Paul Reed
Compares email sanitizers at CSS parsing, serialization, style-scope and browser-evaluation boundaries. Worked probes distinguish remote-image blocking, mock attribute extraction and presentation effects. The examples…
-
Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website Run Code on Your PC
James Arnott
A Chrome extension exposed its native Windows helper to messages from any web page. An attacker could use path traversal in the helper's PKCS#11 library path to make LoadLibrary execute a local DLL, turning a visit to…
-
Trusted Publishing, Untrusted Branch: Inside the Red Hat npm Compromise
François Proulx
Reconstructs an npm compromise in which ephemeral branches retained a trusted workflow filename and published through OIDC. Event actors and signed attestations reveal the branch that produced each package…
-
Turning IDN edge cases into typosquats
Ian Muscat and Leanne Briffa
The article models current Chromium IDN display and navigation checks, then uses same-script breaker characters with surviving skeletons to build visually deceptive domains. It tests live registrations, registry…
-
Two Bypasses for Chrome's Sanitizer API
Adam Kues and @searchlightsec
Two ways past Chrome's built-in Sanitizer API, including a javascript: URL that survives sanitisation because a U+2028 line separator splits the scheme token the parser checks against the one it later resolves.
-
Unauthenticated RCE in Taskcluster via a GraphQL filter reaching sift's `$where`
griffinf
Traces an anonymous Taskcluster GraphQL filter into sift’s JavaScript-evaluating $where operator. The report identifies a scope that guarantees nonempty input and uses propagated error text to observe service-side…
-
Unicode-dot normalization bypasses Node.js TLS wildcard depth checks
Node.js project
Normalizes Unicode dot separators before wildcard hostname validation and supplies a regression test for resolver/verifier disagreement. The change prevents a certificate wildcard from matching an apparent single label…
-
uXSS on Samsung Browser (CVE-2025-58485 · SVE-2025-1879)
Omid Rezaei and Yashar Shahinzadeh
Reverse-engineers Samsung Internet intent handling to distinguish a guarded Bixby path from another exported activity accepting a javascript: URL in the existing tab. The final route differs from the exploratory Frida…
-
Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
PhishU
An adversary-in-the-middle flow captures a Google password-manager sync PIN, persists access with an attacker-owned passkey and joins the victim's security domain from a new device. The chain releases synchronized…
-
We Need to Talk About CSRF Again
Amirmohammad Safari
Two ways a cross-origin POST skips the CORS preflight while the server still parses the body as JSON. Sending it as a Blob with no type leaves no Content-Type header, which FastAPI read as implicit JSON; and Chromium…
- Web Cache Overflow: Exploiting Imprecise Keys for Cache Degradation and Beyond Matteo Golinelli, Kaan Onarlioglu and Bruno Crispo
-
What's in a tag name? JavaScript, apparently
Gareth Heyes
JavaScript hidden in an HTML tag name becomes a payload source when an executable handler reads and transforms that name. The article develops a reusable XSS construction from browser parsing and string behavior; its…
-
What's in Your Agent's Context? Context Privilege Escalation Attacks against AI Agent Harness
Zichuan Li, Jian Cui, Ashley Chen, Xiaojing Liao and Luyi Xing
CoRA discovers which files and metadata enter an agent's context, then checks their message roles and persistence. The paper maps sixteen vectors and five attack chains; its contribution is a systematic harness audit…
-
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Yarden Porat
Cloudflare Code Mode runs model-written code in workerd, the V8-isolate runtime that also provides tenant isolation for Cloudflare Workers, so untrusted code shares a single process. The research reports five…
-
When Audits Fail Part 2: From Pre-Auth SSRF to RCE in TRUfusion Enterprise
RCE Security GmbH - Your European Partner for Offensive Security
Chains TRUfusion Enterprise's absolute-URL proxy behavior into SSRF against an internal Axis2 service, then combines a default credential and path traversal to upload a web shell. The result is another unauthenticated…
- When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online Payments Yongkang Xiao, Jing Chen, Min Shi, Kun He, Qiyi Deng and Ruiying Du
-
When Cache Poisoning Meets LLM Systems: Semantic Cache Poisoning
Guanlong Wu, Taojie Wang, Yao Zhang, Zheng Zhang, Jianyu Niu, Ye Wu and Yinqian Zhang
A semantic cache reuses one user's LLM answer for any later query judged similar enough, which makes a cache entry shared state. The paper crafts a query that embeds close to a target question, takes its cache slot, and…
-
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
Adrian Denkiewicz
Examines CFITSIO extended filename syntax behind apparently read-only image operations. Input fetching, output copying, raw-byte conversion and a writable network backend compose into local file writes, server-side…
-
When HTTP 402 Meets the Blockchain: Risks on Emerging x402 Payments
Qinying Wang, Yong Yang, Yuan Chen, Shouling Ji and Mathias Payer
x402 extends HTTP 402 with a payment negotiation flow and delegates proof verification and on-chain settlement to third-party facilitators, so one facilitator becomes shared payment infrastructure for many independent…
-
When Two Parsers Disagree: Exploiting Query String Differentials for XSS
Amirmohammad Safari
Uses a small Express application to explain mismatches between extended qs parsing and browser URLSearchParams. Bracket interpretation, normalized keys and a parameter-count cutoff let one parser validate a different…
-
When Your VPN Opens Your Private Network to the Public
rootxharsh
Analyzes JWT algorithm confusion in PAN-OS GlobalProtect Cloud Authentication Service deployments, including shared signing-certificate and enrollment prerequisites. Explains how an established cryptographic failure…
-
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253)
Piotr Bazydlo
Reviews the trust boundary between Splunk's management interface and its PostgreSQL sidecar. Database authentication and connection parameters are relied on by maintenance operations without equivalent application…
-
Wrestling with a Python: Escaping Copilot Studio’s AI-Guarded Sandbox
Simon Maxwell-Stewart, Ryan Hausknecht and Phantom Labs®
Investigates Copilot Studio’s LLM guard and in-process Python restrictions separately. Introspection reveals sandbox code, a legacy execution path carries an encoded payload into worker modules, and output and…
-
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE
André Baptista, Rafael Castilho and Bruno Mendes
A graded catalogue of arbitrary-file-write to RCE sinks, plus new ones. Path resolution stops at the first failing component, so the errno of a failed write - read through status code, body length or latency…
- XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638) Nigusu Kasahun
-
YAML Merge Tags and Parser Differentials
The DarkForge Labs Blog
Constructs a single YAML document whose merge keys and explicit merge tags resolve to different values in Go, Ruby, Node.js and Python parsers. The work provides compact test cases for studying security decisions made…
-
You're Not Supposed To ShareFile With Everyone (CVE-2026-2699 & CVE-2026-2701)
Sonny
Traces a ShareFile StorageZones chain involving continued execution after an authentication redirect and downstream configuration and upload handling. The analysis distinguishes authorization checks from the point at…
-
Your House Has an FFmpeg Problem
Jia Hao Poh
Home Assistant's Wyoming announce service passes media_id straight to ffmpeg as -i, and its scheme blocklist covers only http/https, letting concat:, file: and subfile: through. Raw files still fail because the command…
-
Your WAF Blocked Us, That Was The Exploit — Remote Agent Takeover via Cloudflare, Sentry and Claude Zero-Day
Ron Bobrov, Nevo Poran and Barak Sternberg
Every source an agent reads is an injection channel: an unauthenticated Sentry event posted with a public DSN, a Datadog log written with a public client token, or a request crafted to trip Cloudflare's managed WAF so…
-
Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers
Matteo Scarlata, Giovanni Torrisi, Matilda Backendal and Kenneth G. Paterson
"Zero knowledge encryption" is a vendor term with no technical meaning, conveying that a server holding an encrypted vault learns nothing about it even when fully malicious. Comparing that claim against Bitwarden…
- Zero-Click RCE in Figma Desktop Benjamin Mamoud (DavenSec)
-
zkLogin: when ZKP is not enough
@brave and Brave Software
Zero-knowledge authorization proves possession of a signed credential without revealing it, and its security is usually argued from the proof alone. zkLogin, the most widely deployed such system, is shown to depend as…