Ethical hackers rock and we think they do not get enough love (tool wise). So we are creating a tool for security analysts, by security analysts!

Remote, Netherlands
Filter
Exclude
Time range
-
Minimum likes
We’ve just published a blog post with the full write-up for this issue, so be sure to check it out! codeanlabs.com/2026/06/cve-2…
We looked into Kdenlive and find out that opening someone else's project was not the best idea, since it could lead to Remote Code Execution. The vulnerability (CVE-2026-45184) has been patched in version 26.04.1, make sure to update and remember: do not trust FFmpeg parameters!
2
11
1,138
We looked into Kdenlive and find out that opening someone else's project was not the best idea, since it could lead to Remote Code Execution. The vulnerability (CVE-2026-45184) has been patched in version 26.04.1, make sure to update and remember: do not trust FFmpeg parameters!
1
4
18
3,814
Two of our Codean Labs colleagues evaluated OpenPGP.js and identified a signature spoofing vulnerability. Writeup includes a PoC where we demonstrate the vulnerability by spoofing a message by the Dutch government's Cyber Security Center! codeanlabs.com/blog/research…
3
10
1,557
At Codean Labs, our mission is to make the world more secure — and what better way than to secure fundamental open source projects? We identified CVE-2025-47934, a critical vulnerability in OpenPGP.js to spoof signatures, see github.com/openpgpjs/openpgp… github.com/openpgpjs/openpgp…
3
7
460
Codean Labs' @b0n0b0__ and @Doyensec's @drw0if discovered CVE-2025-32464, a heap-buffer overflow in HAProxy. Read our write-up here: codeanlabs.com/blog/research…
6
9
693
We just reached over 1,000 commits on Codean 🎉 Just a few thousand more and I am sure Codean will be done by then 😉
2
233
We are finally catching up on some basic capabilities everyone expects, but are still darn hard to get right! Finally, landed on SCIP and SCIP indexers to have code intelligence that also enables us to create unique and cool features in the future. Stay tuned for more!
2
286
Another day another high impact #CVE-2024-29511 on #Ghostscript ≤ 10.02.1. it leads to an arbitrary file read/write (under certain conditions) outside of the -dSAFER sandbox. You can find all details about this #vulnerability on our blogpost. codeanlabs.com/blog/research…
2
3
334
We found #CVE-2024-29510, a format string vulnerability in Ghostscript ≤ 10.03.0. It enables attackers to gain Remote Code Execution (#RCE) while also bypassing all sandbox protections. It has significant impact so please update Ghostscript! codeanlabs.com/blog/research…
1
7
523
We found a vulnerability in Mozilla’s PDF.js (CVE-2024-4367 and CVE-2024-34342 via react-pdf) resulting in arbitrary JavaScript execution when opening a malicious PDF. This results in XSS on many web- and even desktop apps. Blog post coming soon! linkedin.com/feed/update/urn…
8
25
8,623
#pentesting projects we do via Codean Labs relied on an older version of Codean. Today we onboarded a pentest project on the NEW platform at codean.io 🎉 We did find some bugs that we fixed and identified the need for more features... Plenty of work for all of us!
2
136
𝗪𝗲 𝗵𝗮𝗱 𝗳𝘂𝗻 𝗱𝘂𝗿𝗶𝗻𝗴 #𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗺𝗲𝗻𝘁 There should be a nice way to look at the code that a Codemark points to. To achieve this, we show you a full blown editor with all the bells and whistles, including Codemarks... No worries, its now fixed 😉
2
107
While many parts of Codean are already #designed and "tested" for #userexperience, implementing much is still tbd! Two parts were really hampering even trying Codean: member management and repository synchronization. Both of these have been just implemented and rolled out!
2
93
Here's a write-up of another vulnerability we found, caused by a lack of input validation. This time it's CVE-2023-38504, a DoS in Sails.js, an MVC framework for Node. Enjoy! codean.review/vulnerability-…
2
153