Public library
Cybersecurity articles
Automated coverage from researcher feeds — text + code extraction, no thumbnails. Sort by recent, popular, or trending.
All sources ×PortSwigger Research RSSGoogle Project ZeroUnit 42 (Palo Alto)r/netsec RSSSchneier on SecurityZero Day InitiativeMicrosoft MSRC BlogTrail of BitsnccgroupCisco TalosPentesterLand WriteupsSecurelist (Kaspersky)Cloudflare Blogr/bugbounty RSSKrebs on Security RSSSANS Internet Storm Center RSSThe Hacker News RSSbleepingGitHub Security Advisories
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
Read →### Summary `token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool. The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`: ```ts getent passwd "${username}" || grep "^...
Prefer original Bugflare research? Browse writeups