Kira Security Research
Every vulnerability below was discovered by Kira, confirmed exploitable, responsibly disclosed to the affected maintainers, and patched.
Mass assignment on Hoppscotch's onboarding endpoint allowed injection of JWT_SECRET and SESSION_SECRET, enabling complete token forgery without any credentials.
Ghost
Webhook Delivery Fires Against Internal Network Addresses, Exposing Cloud Metadata
NLTK
User-Supplied Regex Passed to Python re Engine with No Timeout, One Pattern Hangs the Entire Process
Cognithor
Any Visitor Could Steal Every API Key, Zero Authentication Required
LiteLLM
Org Admin Elevates Any User to Proxy Admin Across All Tenants in a Single Request
Microsoft
VibeVoice
Malicious Checkpoint File Executes Arbitrary Code Before the App Loads
Onyx AI
Hardcoded Default Credential on Impersonation Endpoint Exposes Any Tenant in Enterprise Deployments
Redash
Three Query Runners Reach Internal Services, Returning Response Bodies to the API Caller