Skip to content

Instantly share code, notes, and snippets.

View alon710's full-sized avatar
💪

Alon Barad alon710

💪
View GitHub Profile
@alon710
alon710 / CVE-2024-43368.md
Created January 24, 2026 22:53
CVE-2024-43368: Trix Editor XSS: The 'Trust Me, I'm Not HTML' Bypass - CVE Security Report

CVE-2024-43368: Trix Editor XSS: The 'Trust Me, I'm Not HTML' Bypass

CVSS Score: 6.5 Published: 2024-08-14 Full Report: https://cvereports.com/reports/CVE-2024-43368

Summary

A logic flaw in Trix Editor's attachment handling allowed attackers to bypass XSS protections by simply mislabeling the content type of malicious payloads.

TL;DR

@alon710
alon710 / CVE-2025-36072.md
Created January 24, 2026 22:44
CVE-2025-36072: Object Graph Chaos: Inside CVE-2025-36072 - CVE Security Report

CVE-2025-36072: Object Graph Chaos: Inside CVE-2025-36072

CVSS Score: 8.8 Published: 2025-11-20 Full Report: https://cvereports.com/reports/CVE-2025-36072

Summary

An authenticated Remote Code Execution (RCE) vulnerability in IBM webMethods Integration caused by unsafe deserialization of object graphs.

TL;DR

@alon710
alon710 / CVE-2025-69256.md
Created January 24, 2026 22:44
CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell' - CVE Security Report

CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell'

CVSS Score: 7.5 Published: 2025-12-31 Full Report: https://cvereports.com/reports/CVE-2025-69256

Summary

The Serverless Framework's experimental Model Context Protocol (MCP) server contained a critical command injection vulnerability. By failing to sanitize directory paths passed to a shell command, the tool allowed attackers—or confused LLMs—to execute arbitrary system commands.

TL;DR

@alon710
alon710 / CVE-2025-14847.md
Created January 24, 2026 22:44
CVE-2025-14847: MongoBleed: The Heartbleed of Databases (CVE-2025-14847) - CVE Security Report

CVE-2025-14847: MongoBleed: The Heartbleed of Databases (CVE-2025-14847)

CVSS Score: 8.7 Published: 2025-12-19 Full Report: https://cvereports.com/reports/CVE-2025-14847

Summary

A critical, unauthenticated heap memory disclosure vulnerability in MongoDB's wire protocol handling allows attackers to bleed secrets—including passwords and AWS keys—directly from server memory.

TL;DR

@alon710
alon710 / CVE-2024-12345.md
Created January 24, 2026 22:44
CVE-2024-12345: CVE-2024-12345: The Ghost in the Shell – Anatomy of a Canary CVE - CVE Security Report

CVE-2024-12345: CVE-2024-12345: The Ghost in the Shell – Anatomy of a Canary CVE

CVSS Score: 6.7 Published: 2025-01-27 Full Report: https://cvereports.com/reports/CVE-2024-12345

Summary

An analysis of the peculiar 'INW Krbyyyzo' vulnerability, a likely placeholder or 'canary' entry designed to track scraping behavior, disguised as a classic ASP.NET resource exhaustion flaw.

TL;DR

@alon710
alon710 / CVE-2025-68131.md
Created January 24, 2026 22:44
CVE-2025-68131: Oversharing is Caring: The Persistent Memory of CVE-2025-68131 - CVE Security Report

CVE-2025-68131: Oversharing is Caring: The Persistent Memory of CVE-2025-68131

CVSS Score: 4.0 Published: 2025-12-31 Full Report: https://cvereports.com/reports/CVE-2025-68131

Summary

A logic flaw in the popular Python cbor2 library allows sensitive data from one decoding session to persist and bleed into subsequent sessions due to improper state management of the 'Value Sharing' feature.

TL;DR

@alon710
alon710 / CVE-2025-54997.md
Created January 24, 2026 22:44
CVE-2025-54997: The Janitor's Key: Turning OpenBao Audit Logs into RCE - CVE Security Report

CVE-2025-54997: The Janitor's Key: Turning OpenBao Audit Logs into RCE

CVSS Score: 9.1 Published: 2025-08-09 Full Report: https://cvereports.com/reports/CVE-2025-54997

Summary

OpenBao and HashiCorp Vault, the literal Fort Knoxes of the DevOps world, suffered a catastrophic logic flaw in their audit subsystems. By abusing the ability to configure audit devices via API, privileged attackers could trick the system into writing malicious code directly to the host filesystem.

TL;DR

@alon710
alon710 / CVE-2025-54418.md
Created January 24, 2026 22:44
CVE-2025-54418: Shells in Your Selfies: CodeIgniter 4 ImageMagick RCE - CVE Security Report

CVE-2025-54418: Shells in Your Selfies: CodeIgniter 4 ImageMagick RCE

CVSS Score: 9.8 Published: 2025-07-28 Full Report: https://cvereports.com/reports/CVE-2025-54418

Summary

A critical OS Command Injection vulnerability in CodeIgniter 4's ImageMagick handler allows unauthenticated attackers to achieve Remote Code Execution (RCE) via malicious filenames or text overlays.

TL;DR

@alon710
alon710 / CVE-2025-69257.md
Created January 24, 2026 22:44
CVE-2025-69257: Oh theshit! From Typo Fixer to Root Shell via Python Injection - CVE Security Report

CVE-2025-69257: Oh theshit! From Typo Fixer to Root Shell via Python Injection

CVSS Score: 6.7 Published: 2025-12-30 Full Report: https://cvereports.com/reports/CVE-2025-69257

Summary

A classic Local Privilege Escalation (LPE) in the 'theshit' command correction utility, allowing unprivileged users to execute arbitrary Python code as root due to unsafe loading of user configuration files.

TL;DR

@alon710
alon710 / CVE-2025-6000.md
Created January 24, 2026 22:44
CVE-2025-6000: Vaulted Severance: Turning Audit Logs into Remote Shells - CVE Security Report

CVE-2025-6000: Vaulted Severance: Turning Audit Logs into Remote Shells

CVSS Score: 7.2 Published: 2025-08-01 Full Report: https://cvereports.com/reports/CVE-2025-6000

Summary

A critical privilege escalation vulnerability in HashiCorp Vault allows privileged operators to achieve Remote Code Execution (RCE) on the host system. By abusing the File Audit Device and Plugin System, an attacker can write executable audit logs to the plugin directory and execute them.

TL;DR