Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

moltenbit

@moltenbit@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security researcher. Bug bounty hunter. Finding vulnerabilities. Occasionally writing about it at moltenbit.net

0 Followers
0 Following
3 Posts
Joined June 27, 2024
blog:
https://moltenbit.net
bluesky:
https://bsky.app/profile/moltenbit.bsky.social
Open post
moltenbit @moltenbit@infosec.exchange
· 3mo ago
RE: https://infosec.exchange/@moltenbit/116608526922719220 Writeup is online: https://moltenbit.net/posts/auditing-openreception/ #cybersecurity #vulnerability #infosec #security
infosec.exchange
0
0
0
0
Open post
moltenbit @moltenbit@infosec.exchange
· 2mo ago
new writeup: three bugs in vinext's alpha, cloudflare's next.js reimplementation that one engineer built with an AI model in about a week for roughly $1,100 in tokens. the good one: vinext checks middleware matchers against the path with the i18n locale prefix still on it, then strips the locale when it resolves the route. /fr/dashboard misses /dashboard/:path*, the auth middleware never runs, and the router serves /dashboard anyway. also a middleware header allowlist that is really a merge, and reflected XSS via unescaped attribute names in the next/head serializer. reported in february, cloudflare fixed all three. https://moltenbit.net/posts/three-bugs-in-cloudflares-vinext-alpha/ #infosec #appsec #cloudflare #nextjs #bugbounty #cybersecurity #security
moltenbit

Three bugs in vinext's alpha, Cloudflare's AI-built Next.js replacement

Three bugs in vinext's alpha, the Next.js replacement Cloudflare built with AI for about $1,100: a middleware auth bypass, a header-sanitization bypass, and a reflected XSS.

0
0
0
0
Open post
moltenbit @moltenbit@infosec.exchange
· 2mo ago
two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there. CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94. CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93. https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj #GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
GitHub

Incomplete tenant scoping in db_toggle_escrow clears secondary escrow backup keys across tenants

## Summary The `db_toggle_escrow` operation in the GlobaLeaks admin API does not consistently scope its ORM update path to the originating tenant. When a non-root tenant admin disables escrow on...

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:56:17 UTC