Security Research

Real vulnerabilities.
Real fixes.

Every report below was confirmed exploitable, responsibly disclosed, and patched by the affected team.

Subscribe via RSS
CVE Disclosure CVE-2026-50160

One unauthenticated HTTP request.
Full server compromise.

Mass assignment on Hoppscotch's onboarding endpoint allowed injection of JWT_SECRET and SESSION_SECRET, enabling complete token forgery without any credentials.

CWE-915 Mass Assignment ≤ v2026.4.1 Self-hosted
Read full report
CVSS Score 10.0
Critical
CVSS v3.1
CVE

Ghost

Medium · Apr 2026

Webhook Delivery Fires Against Internal Network Addresses, Exposing Cloud Metadata

CVSS 5.5 · CWE-918 · CVE-2026-53945 · GHSA-ch52-px8q-f22j ↗

Read full report

NLTK

High · Aug 2026

User-Supplied Regex Passed to Python re Engine with No Timeout, One Pattern Hangs the Entire Process

CVSS 8.7 (v4) · CWE-1333 · CVE-2026-80205 ↗ · GHSA-rrv8-h7p8-rx55 ↗

Read full report
Vulnerabilities

Cognithor

Critical · Apr 2026

Any Visitor Could Steal Every API Key, Zero Authentication Required

CVSS 9.8 · CWE-306

Read full report

LiteLLM

Critical · Apr 2026

Org Admin Elevates Any User to Proxy Admin Across All Tenants in a Single Request

CVSS 9.0 · CWE-862 · CWE-269

Read full report

Microsoft

VibeVoice

High · Apr 2026

Malicious Checkpoint File Executes Arbitrary Code Before the App Loads

CVSS 7.8 · CWE-502

Read full report

Onyx AI

High · Jun 2026

Hardcoded Default Credential on Impersonation Endpoint Exposes Any Tenant in Enterprise Deployments

CVSS 8.7 · CWE-798 · No advisory published

Read full report

Redash

Medium · Apr 2026

Three Query Runners Reach Internal Services, Returning Response Bodies to the API Caller

CVSS 6.8 · CWE-918

Read full report

Want Kira on your codebase?

See what’s actually exploitable before attackers do.

Start scanning →