slcyber.io
Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-10-10.
| Date Added | Resource | Excerpt |
|---|---|---|
| 2026-10-10 2026 | A JPEG, a Race, and a Ghost: Breaking Discourse's Image PipelineRCE | This post details a vulnerability discovered in Discourse's image processing pipeline. The bug involves a race condition and a bypass of security checks, allowing an attacker to upload and execute arbitrary code by manipulating specially crafted JPEG files. The vulnerability could lead to remote code execution on the Discourse server. |
| 2026-09-10 2026 | Out of Bounds, Out of Sandbox: RCE in Go JavaScript EngineRCE | Library detailing a Remote Code Execution (RCE) vulnerability in the Goja JavaScript engine, found within applications like Grafana k6, PocketBase, Nuclei, and Zendesk. The vulnerability arises from an out-of-bounds heap write in `TypedArray` methods (`with` and `toReversed`) due to an incorrect offset calculation, exacerbated by Go's `unsafe` package bypassing runtime bounds checking. Successful exploitation involves heap spraying and manipulating `ArrayBuffer` structures to achieve arbitrary read/write capabilities, ultimately leading to sandbox escape and code execution. |
| 2026-07-21 2026 | I found a WordPress RCEs with GPT5.6 and $25AIRCE | Tool that leverages GPT5.6 Sol Ultra to discover RCE vulnerabilities in WordPress, demonstrated by finding a pre-authentication SQL injection that escalates to RCE. The process involved adapting a prompt designed for mathematical conjecture solving to analyze WordPress source code, utilizing multi-agent exploration for six hours, and costing approximately $25 in LLM usage. The tool is available at wp2shell.com for users to check their WordPress instances. |
| 2026-07-15 2026 | Smashing the ServiceNow Sandbox – Pre Authentication RCERCE | Library for finding pre-authentication RCE vulnerabilities in ServiceNow, focusing on the GlideRecord system and its "javascript:" filter operator. This resource details how to leverage the `javascript:` prefix within `addQuery` calls to achieve remote code execution, bypassing ServiceNow's additional script sandbox by exploiting the `gs.include()` function to access script includes and ultimately gain full compromise of the instance and connected proxy servers. |
| 2026-06-27 2026 | CargoWise WebTracker - The keys were in the cargoSecrets | Library for securing CargoWise WebTracker, a logistics platform. This resource details hardcoded symmetric keys (3DES and AES-256-CBC) used for encrypting query string parameters and authentication tokens. It demonstrates how these keys enable authentication bypass via an "auto-login" feature and session persistence on handler endpoints, potentially allowing unauthorized access to sensitive shipment and booking information. |