Catalog changelog
This page is the catalog. Vulnerability headlines stay on the news page.
2026-10-04
- MCP revision 2026.10.1 connects all seven collections in the research-library snapshot through compact overview, search, and individual-record tools.
- Research results include primary-source links, snapshot provenance, bounded sections, and pagination. The
research-briefprompt supports focused reading in smaller context windows. - Added a static Misconfig.ai beta advertisement using its supplied branding, plus the GK Data publisher badge.
2026-09-27
- Hunt briefs added for business logic, subdomain takeover, prototype pollution, mass assignment, reset and magic links, clickjacking, cloud object storage, provisioning, and billing. Each one links a playbook.
- Skills added for cloud object storage, provisioning, and billing. The session skill now includes reset binding. The access-control skill now includes mass assignment.
- Map pages added: severity labels, coverage, chain index, API Top 10:2023, and what you are holding.
- Scope sort on Utilities matches hosts and keywords to a skill in the browser. The list is not sent to the hosted MCP.
- Product revision remains 2026.09.1. The MCP protocol date remains 2026-07-28. Vulnerability headlines stay on news.
2026-09-28
- Eight public disclosure cards were added from disclosed HackerOne reports: OAuth redirect, cache deception, smuggled cache, SSRF filter gap, verification race, reflected CORS origin, negative order quantity, and an AI Playground session that could act on a connected MCP server. Each card links the report and leaves out the request body.
- HackerOne, Bugcrowd, and Intigriti platform pages now quote what those companies publish about scope, disclosure, and safe harbor, with a link to the policy.