Pinned Tweet
Happy to share my first article with @zhero___, which is also my first CVE (CVE-2025-29927) on the largest JS framework: Next.js. A critical vulnerability that impacts a wide range of sensitive sectors across the internet.
the research paper is out: Next.js and the corrupt middleware: the authorizing artifact result of a collaboration with @inzo____ that led to CVE-2025-29927 (9.1-critical) zhero-web-sec.github.io/rese… enjoy the read!
9
14
221
20,000
inzo retweeted
Pleased to publish a browser-related research paper (w/@inzo____) titled: One trigram at a time: XSLeak via Universal CSS Injection and DoS in Opera (GX) The title speaks for itself. Enjoy the read! zhero-web-sec.github.io/rese…
5
63
266
27,978
inzo retweeted
Paper currently being written. Expected to be the next publication, God willing. As no companies have yet been found whose vision and values truly align with ours, sponsorships, partnerships, and selective intellectual property transfers related to ongoing and future research remain open for discussion.
can merely visiting a website lead to cross-site data exfiltration from any site without user interaction? a ""minimal"" PoC has been validated, successfully exfiltrating, as a demonstration, the victim’s gmail address report submitted, hoping to provide more details soon
4
85
5,855
inzo retweeted
New short article on a real-world exploitation case rather than pure research, demonstrating how a specific mistake in Next.js can lead to a systematic zero-click SXSS on its latest versions (w/@inzo____): Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js zhero-web-sec.github.io/rese…
6
66
358
23,678
inzo retweeted
Now open to sponsorships, partnerships, and selective intellectual property transfers related to ongoing and future research. Current model: fully independent vulnerability research funded through bug bounty activity, with no consulting or commercial services. Interested parties can reach out via DM or via the email listed on the blog.
I’ve received several similar offers over the past few months from companies of various sizes involving conducting research + writing of the related papers, which generally included: - transferring research intellectual property - per-research payment, sometimes with a fixed fee
3
81
9,560
inzo retweeted
Happy to publish our first research of the year on the SvelteKit framework, downloaded over 800,000 times per week, which led to CVE-2025-67647 (w/@inzo____): Avoiding the paradox: A native full-read SSRF and one‑shot DoS in SvelteKit zhero-web-sec.github.io/rese… Enjoy the read
8
60
346
16,562
inzo retweeted
Voting is now open, with three of my papers nominated: 1. Eclipse on Next.js: Conditioned exploitation of an intended race-condition 2. Next.js, cache, and chains: the stale elixir 3. Astro framework and standards weaponization take a moment to vote! portswigger.net/polls/top-10…
5
7
114
5,359
No doubt I’ll be voting for these two amazing pieces of research
honored to see two of my research works selected for the initial nominations they’ve been the most fruitful for me in practice, with ongoing discoveries of vuln assets, incl. several major platforms, and six figures in rewards If they helped you in any way, consider voting-14/01
2
26
1,566
It was an excellent year of collaboration with my brother, during which I learned many things and we achieved a lot of results. Find out what next year will bring.
1
9
984
inzo retweeted
We unfortunately won’t be able to publish our latest paper before the end of 2025 as the maintainers chose to delay it until early January. Still, it’s been a productive year of zero-day discoveries, with a focus on frameworks, many of which were shared on the blog. 2025 Recap:
6
12
177
14,557
inzo retweeted
second research on Astro, a shorter paper than usual, which led to CVE-2025-64764 (w/ @inzo____): Unlocking Reflected XSS in the Astro framework zhero-web-sec.github.io/rese… all applications using the Server Island feature are vulnerable
release of our new paper (w/ @inzo____) which resulted in CVE-2025-64525: Astro framework and standards weaponization from path-based middleware protection bypass to potential SSRF & XSS + full bypass of CVE-2025-61925 on @astrodotbuild zhero-web-sec.github.io/rese…
6
38
297
21,190
Research from @zhero___ and @inzo____, breaking yet another popular framework. This time, it's @astrodotbuild. Hackers with character, enjoy the read!
Replying to @e11iptic
spent more time writing than reading this week : zhero-web-sec.github.io/rese…
6
34
6,497
inzo retweeted
release of our new paper (w/ @inzo____) which resulted in CVE-2025-64525: Astro framework and standards weaponization from path-based middleware protection bypass to potential SSRF & XSS + full bypass of CVE-2025-61925 on @astrodotbuild zhero-web-sec.github.io/rese…
11
77
343
53,556
inzo retweeted
to echo my last post, your big, influential app with millions of users is surely secure against this probably the most surprising(?) vulnerability of my short career; sometimes you just need to reach out your arm (almost literally), right @inzo____?
8
4
166
8,238
inzo retweeted
frameworks, frameworks with @inzo____
2
6
156
21,982
inzo retweeted
new discovery: cache poisoning on next.js - CVE-2025-49826 indefinite caching of a 204 response, rendering the affected pages inaccessible affected versions: >15.0.4 and <15.2.0 there will be no research paper for this one
back to work with @zhero___ and a new vulnerability on @nextjs that led to CVE-2025-49826 both routers are impacted: app router: framework's cache is directly impacted on ISR pages, regardless of the presence of a CDN pages router: SSR pages only + requires a misconfigured CDN
14
82
471
39,151
back to work with @zhero___ and a new vulnerability on @nextjs that led to CVE-2025-49826 both routers are impacted: app router: framework's cache is directly impacted on ISR pages, regardless of the presence of a CDN pages router: SSR pages only + requires a misconfigured CDN
4
19
216
54,039
inzo retweeted
Bug bounty, feedback, strategy, and alchemy frequently asked for advice, roadmaps, and more, I finally took the time, after 2–3 years of bug bounty, to write down my vision, thoughts and perspective on the subject non-technical, no research this time! zhero-web-sec.github.io/thou…
20
85
427
30,048
After a few days off, I'm back to work with @zhero___, and we've just reported a new high-severity vulnerability in a major open-source framework.
10
3
119
8,110
In the meantime, @zhero___ published a very interesting piece of research
publication of my latest modest paper; Eclipse on Next.js: Conditioned exploitation of an intended race-condition - (CVE-2025-32421) enabling a partial bypass of my previous vulnerability, CVE-2024-46982 by chaining a race-condition to a cache-poisoning zhero-web-sec.github.io/rese…
13
1,945