The Hidden Layer.
A living archive of real CVEs, writeups, and defensive fixes. No noise. Only signal.
Filter examples: tag:xplatform:xdiff:x
LATEST
eMAPT: My Honest Take
My honest take on eMAPT after passing it: a beginner-to-mid-level mobile-security certification with practical work and some theory.
- emapt
- mobile-security
- android
CVE-2026-14361: HashiCorp Consul Template's writeToFile Path Redirection and File Overwrite
Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output to escape the intended directory and overwrite a preexisting file.
- symlink
- path-redirection
CVE-2026-5061: HashiCorp Consul Template's sandbox_path Bypass Through a Symlink TOCTOU
Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the link between those operations turned an in-sandbox file reference into an out-of-sandbox file disclosure.
- symlink
- toctou
Visual Studio Code: Trusted MCP Hover Rendering -> command: Execution
Attacker-controlled MCP server descriptions reached a trusted hover markdown surface in VS Code, which preserved `command:` links and let a click trigger built-in product actions.
- vscode
- microsoft
- mcp
CVE-2026-34048: Coolify's Terminal Websocket Authorization Bypass from Low-Privilege Team Member to Server Shell
Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and execute commands on team servers.
- authorization
- rbac
CVE-2026-42089: yeoman-environment's Silent Package Installation from Caller-Supplied Names
A local package installation helper trusted caller-supplied package names too much. In yeoman-environment, missing generators could be installed without user confirmation, turning attacker-controlled project metadata into a package-install and code-execution path.
- supply-chain
- npm
CVE-2026-46558: Plane’s Cross-Workspace Asset Authorization Bypass in V2 Asset Endpoints
Plane’s V2 asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one authenticated user read, copy, delete, and overwrite assets in other workspaces.
- idor
- authorization
CVE-2026-45806: Penpot's Authenticated SSRF in Remote Image Import
Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because attacker-controlled URLs crossed into a redirect-following server fetch path without destination filtering.
- ssrf
- clojure
CVE-2026-34207: Typebot's SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook URLs reach loopback, metadata, and private network targets.
- ssrf
- dns
CVE-2026-46552: NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation
A public shared-base link in NocoDB inherited member-management permissions, which let an anonymous share session enumerate members, invite arbitrary users into the base, and convert temporary link access into durable authenticated membership.
- authorization
- access-control
CVE-2026-34212: Stored XSS in Docmost Attachment Nodes via Unsanitized URL Schemes
Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin.
- xss
- stored-xss
CVE-2026-34213: Docmost's Attachment Overwrite Shortcut That Let One Page Clobber Another Page's File
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace.
- authorization
- idor
CVE-2026-33146: Docmost Public Share Search Leaks Restricted Child Page Metadata
A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public share viewers could still leak through public share search results.
- authorization-bypass
- information-disclosure
CVE-2026-34828: listmonk’s Session Persistence After Password Reset and Password Change
A stolen session did not die when the password changed. In listmonk, previously issued authenticated sessions remained valid after both password reset and password change, turning credential recovery into incomplete recovery.
- session-management
- account-recovery
CVE-2026-33936: python-ecdsa’s DER Length Validation Bug That Turned Malformed Input into Crashy Key Parsing
Malformed DER with truncated length fields was accepted instead of rejected, and that let untrusted input reach an internal exception path during key parsing.
- dos
- python
CyCTF Luxor Final: QuickPaste - Title Injection -> CSP Gadget Abuse -> Admin Bot Cookie Exfil
The title field is reflected as raw HTML, a weird built-in callback gadget turns malformed markup into JavaScript, and the admin bot hands over the flag through a readable same-origin cookie.
- dom-clobbering
- xss
- csp
CVE-2026-32722: Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata
A profiling tool turned command-line metadata into executable HTML because one attacker-controlled field crossed into a browser sink without escaping.
- xss
- python
CyCTF Luxor: Clear - Upload Traversal → Nginx Cache Poisoning → Admin Bot Flag Exfil
User-controlled filename becomes arbitrary file write, trusted cached JS gets replaced, admin bot executes it, and the flag gets exfiltrated.
- web
- path-traversal
- cache-poisoning
eWPTX: What Made It Worth Taking
My honest take on eWPTX after finishing it in roughly three hours: broad, practical, and worth more than a scanner-driven web cert.
- ewptx
- penetration-testing
- certification
mrma: Analyze trust-boundary header influence on HTTP responses.
HTTP Trust Boundary Analyzer - replay requests, mutate headers safely, and quantify response influence.
- mrma
- security-tools
- penetration-testing
eJPT: What I Think After Passing
My honest take on eJPT after passing it with 97%: a good first practical certification, but not more than that.
- ejpt
- penetration-testing
- offensive-security
0xl4ugh CTF: GAP - JSON/JS Discrepancy → Lodash.template RCE
One JSON key becomes multiple JS parameters → values run out → ES6 default param executes.
- web
- RCE
- 0-day
NSE 4 & NSE 5: My Honest Take
What I got from the Fortinet NSE 4/NSE 5 path, where it helped, and what current candidates need to know before following an old FCP guide.
- fortinet
- nse5
- nse4
CyCTF: News Revenge - NoSQLi Auth Bypass → XML Content-Type Bypass → Stored XSS → Admin Cookie Exfiltration
Authentication bypass via MongoDB NoSQL injection chained with XML content-type filter bypass to land stored XSS, executed by admin to exfiltrate cookies containing the flag.
- nosql
- xss
- web