Public library
Cybersecurity articles
Automated coverage from researcher feeds — text + code extraction, no thumbnails. Sort by recent, popular, or trending.
All sources ×PortSwigger Research RSSGoogle Project ZeroUnit 42 (Palo Alto)r/netsec RSSSchneier on SecurityZero Day InitiativeMicrosoft MSRC BlogTrail of BitsnccgroupCisco TalosPentesterLand WriteupsSecurelist (Kaspersky)Cloudflare Blogr/bugbounty RSSKrebs on Security RSSSANS Internet Storm Center RSSThe Hacker News RSSbleepingGitHub Security Advisories
JSONata: Arbitrary Code Execution via crafted JSONata expressions
Read →## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function: https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705 This ...
Prefer original Bugflare research? Browse writeups