Codex command approval relied on inconsistent parser semantics
ZDI awarded Compass Security USD 40,000 for this distinct Pwn2Own Berlin entry.
INVulnerability family
Separation between untrusted data and executable interpretation. 12 disclosures · 8 related references · 3 diagrams.
Connected collection
ZDI awarded Compass Security USD 40,000 for this distinct Pwn2Own Berlin entry.
A PostgreSQL encoding-validation failure earned Team Bugz Bunnies a $30,000 individual-entry award at ZeroDay.cloud. The vendor subsequently issued CVE-2026-2006.
A Google-rewarded report connected an adjacent CI misconfiguration with insufficient separation of automation trust, creating a potential Angular supply-chain impact.
A Kestrel request-framing report earned a researcher-reported USD 10,000 award.
Google awarded USD 20,000 for the Colab-export finding in a multi-finding research article.
A researcher reported one dependency-confusion finding affecting GitHub build and development services and a $20,000 award.
ZDI awarded Wiz researchers USD 30,000 for this single Pwn2Own Berlin 2025 entry.
A browser-IDE trust-boundary report received a USD 22,500 award.
One Workspace data-disclosure finding within a broader research article earned USD 20,000.
The researcher assigns a separate $62,500 award to the client-side finding labeled Bug #1.
The researcher attributes a USD 250,000 award to the article’s separately identified backend finding, Bug #2.
A USD 66,000 researcher-reported award illustrates how weak message authentication and unsafe rendering can invalidate an SDK trust boundary.
Connected collection
Django confirms CVE-2026-1312: application-controlled column aliases could cross from metadata into SQL structure when used across relation filtering and ordering. Exploitability requires an application to admit…
Researchers describe client-supplied metadata becoming authoritative response metadata through unusual middleware header copying. This changed how a dynamic App Router representation was interpreted; an external shared…
Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.
OWASP explains origin checks, expected message formats and treating exchanged content as data. These controls address different assumptions at browser communication boundaries.
Defense-in-depth guidance for LLM applications that consume untrusted content or invoke tools. Covers data provenance, least privilege, action authorization, monitoring, and the limitations of guardrails.
Runtime documentation distinguishes the selected executable, its arguments, and shell interpretation. Python does not implicitly select a shell, but Windows may launch batch files through one. The companion shlex…
The maintainer describes inconsistent escaping across structured-object serialization: some object-derived strings entered generated JavaScript without equivalent protection. Code execution requires attacker-influenced…
Learn to assess software supply-chain assurance using distinct source and build tracks. The build track progresses from recording provenance to authenticated hosted builds and stronger platform isolation. Build…
Connected collection
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Original defensive model combining OWASP messaging and authorization guidance with the linked historical cases. These are independent design checks, not a vendor patch diagram or an operational reproduction.
Editorial conceptual model combining the Angular case with SLSA build guidance. The case supports separating automation trust and shared build state; the consumer verification gate is a general design synthesis, not a…
Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.
GitHub snapshot 2026-10-04
53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software
| / | Focus search on this page |
| Ctrl K | Search everything (command palette) |
| 1-9 | Library, Generator, Playbooks, Gadgets, Checklists, Payloads, Bypasses, Utilities, Reports |
| 0 | AI / MCP connector |
| j / k | Move selection down / up |
| Enter | Expand / open selected |
| c | Copy primary command of selected |
| f | Toggle favorite on selected tool |
| Esc | Clear search / close |