// index
Writeups
Public vulnerability research, disclosure writeups, and class-of-vuln deep dives. Client identifiers from confidential engagements are redacted; the technical substance is preserved.
12 of 12
- Disclosure CVE-2026-63358 High 7.3 8 min
FileGator v7.14.0: Privilege Escalation via Unvalidated chmod Endpoint
A low-privileged authenticated user with the chmod permission could set arbitrary Unix special permission bits (setuid, setgid, sticky) on any file or directory they could reach across all three storage adapters (Local, SFTP, FTP). With one recursive call, the entire repository tree could be flipped to setuid root.
- #privilege-escalation
- #input-validation
- #php
- #responsible-disclosure
- #cwe-732
- Disclosure CVE-2026-59972 High 8.1 8 min
unzipper: Zip Slip Arbitrary File Write via a Sibling-Prefix Path Bypass
unzipper already blocks classic ../../ Zip Slip; it was patched for CVE-2018-1002203 years ago. But the guard it shipped was a string-prefix check (extractPath.indexOf(destination) != 0), and a string prefix is not a directory boundary. An archive entry named ../dest-evil/x escapes /tmp/dest into the sibling /tmp/dest-evil, which the old check happily accepts because the path starts with the destination string. One crafted entry writes a file outside the extraction root. CVE-2026-59972: reported, root-caused, and patched upstream, on a package pulling ~29M downloads a week.
- #zip-slip
- #path-traversal
- #arbitrary-file-write
- #javascript
- #npm
- #supply-chain
- Disclosure CVE-2026-55091 High 7.5 7 min
flat-to-nested: Prototype Pollution via a __proto__ Parent Key
flat-to-nested turns a flat list of records into a parent/child tree by using each record's id and parent field directly as object keys on a plain {} lookup table. A single record whose parent is the string "__proto__" walks the prototype chain to Object.prototype and writes attacker-controlled data onto every object in the process. The package's exact core purpose (building trees from DB/REST/user-derived records) is the delivery path. CVE-2026-55091, patched in 1.1.2.
- #prototype-pollution
- #javascript
- #npm
- #supply-chain
- #responsible-disclosure
- #cwe-1321
- Disclosure CVE-2026-54283 High 7.5 5 min
Starlette: Form-Parser Limits Silently Ignored for URL-Encoded Bodies
Starlette's Request.form() advertises max_fields, max_files, and max_part_size as resource-consumption guards. They are correctly enforced for multipart/form-data but quietly dropped on the application/x-www-form-urlencoded path, so any FastAPI or Starlette app that calls request.form() and accepts URL-encoded bodies is exposed to a one-request event-loop-blocking DoS.
- #dos
- #resource-consumption
- #python
- #asgi
- #fastapi
- #cwe-770
- Disclosure High 8.1 8 min
decompress-zip: Zip Slip Arbitrary File Write via a Sibling-Prefix Bypass
decompress-zip was patched for classic ../../ Zip Slip back in 0.3.2. That fix still holds, but the guard it added is a string-prefix check (destination.indexOf(options.path) !== 0), and a string prefix is not a directory boundary. A zip entry resolving to /uploads/userdir-EVIL/x escapes /uploads/userdir because the string starts with the destination. The same library already uses a correct path.relative() check for its symlink handling, which makes the inconsistency glaring. The package is abandoned, the published security contact is a dead mailbox, and no patched version exists, so this is a public disclosure with mitigation guidance.
- #zip-slip
- #path-traversal
- #arbitrary-file-write
- #javascript
- #npm
- #supply-chain
- Research Critical 9.9 9 min
From Domain User to Golden Ticket: PetitPotam → AD CS ESC8 → DCSync
A full internal Active Directory compromise chain, walked end-to-end. Starting from an unprivileged domain account on a three-DC Windows Server 2019 forest, the assessment coerced a Domain Controller into authenticating against an attacker-controlled SMB relay, relayed the NTLM auth to AD Certificate Services, obtained a machine certificate, used it to issue a TGT, and dumped krbtgt, closing with a Golden Ticket for indefinite, log-quiet Domain Admin persistence.
- #active-directory
- #ad-cs
- #esc8
- #petitpotam
- #ntlm-relay
- #golden-ticket
- Class Critical 9.8 8 min
Sequelize Raw-Query SQL Injection via the Sort Parameter
Sequelize is the default ORM for most Node.js teams, and almost every team using it has at least one place where they reach past the parameterised API and write a raw query, typically to handle a feature the high-level API doesn't ergonomically support, like ORDER BY on a user-supplied column. That single shortcut is where the SQLi sneaks in. Walked end-to-end against a PostgreSQL backend serving PHI: error-based exfiltration in one path and time-based blind in another, both from the same root cause.
- #sql-injection
- #sequelize
- #postgresql
- #orm-bypass
- #node-js
- #class-of-vuln
- Class Critical 9.8 6 min
One-Click Account Takeover via OAuth Implicit Flow and Lax Redirect URI Validation
Azure AD tenants that still allow the OAuth 2.0 implicit grant (paired with redirect URI lists that accept arbitrary domains, or with hosts in the allow-list that proxy redirects) give an attacker a single-link account takeover. The victim clicks a normal Microsoft login URL, authenticates against their real tenant, and the access token is delivered to an attacker-controlled domain in the URL fragment of the response.
- #oauth
- #azure-ad
- #entra-id
- #account-takeover
- #identity
- #class-of-vuln
- Class Critical 9.0 6 min
Angular bypassSecurityTrustHtml + Missing httpOnly = Session Hijack on a PHI App
Angular ships a sanitiser specifically to keep developers out of trouble. Calling bypassSecurityTrustHtml() turns that protection off for the rest of the request lifecycle, and most codebases that reach for it do so without grasping how complete the bypass is. Combine that with an auth-token cookie that's missing the httpOnly attribute, and the result is a single stored payload that exfiltrates every viewer's session, including the administrators reviewing the affected record. Walked end-to-end on a HIPAA-scope application; client identifiers redacted.
- #xss
- #session-hijack
- #angular
- #hipaa
- #auth
- #class-of-vuln
- Class Critical 9.1 9 min
Auditing Firebase: Open Registration + Permissive Firestore Rules = Full Production CRUD
Firebase makes shipping a backend a forty-minute exercise. It also makes shipping the wrong backend a forty-minute exercise. The single most common misconfiguration I encounter against Firebase-fronted applications is the combination of open user registration (left enabled from the dev phase) and Firestore security rules that grant blanket access to authenticated users. Together they collapse the entire production database into something any internet user can read, write, and delete. Walked end-to-end against a real production instance, sanitised.
- #firebase
- #firestore
- #cloud-misconfiguration
- #authorisation
- #class-of-vuln
- Incident Response Critical 10 min
The Axios npm Supply-Chain Attack: One Org's Twenty-Four Hours
On March 31 2026, two compromised versions of the axios package were published to npm carrying a hidden cross-platform RAT attributed to BlueNoroff (a Lazarus Group subunit). This is the incident-response narrative from inside one organisation that was in scope and survived without compromise: what we did between the public disclosure landing in our Slack and the final containment ticket closing the next afternoon. Times, evidence, decisions, the gaps we found in our own visibility along the way.
- #incident-response
- #supply-chain
- #npm
- #lazarus
- #blueNoroff
- #blue-team
- Research High 8.8 5 min
Bypassing AWS WAF's 8 KB Body Inspection Limit for Stored XSS
AWS WAF inspects only the first 8 KB of a request body by default. A modest image upload endpoint, fronted by an otherwise solid WAF rule set, can be coerced into accepting a stored XSS payload by padding the request past that threshold and parking the script tag in the bytes the inspector never sees. The payload then sits in object storage and waits to be served back.
- #aws-waf
- #stored-xss
- #waf-bypass
- #research
- #class-of-vuln
Nothing matches that combination yet.