The Blog
Technique, methodology, and research notes from authorized offensive engagements.

Open WebUI SSRF - Redirect-Based Validation Bypass (CVE-2026-45401)
SSRF in Open WebUI's web fetch: validate_url checks the original hostname but the loader follows redirects, letting any authenticated user reach in...

Open WebUI - Unauthenticated RAG Configuration Disclosure (CVE-2026-45397)
A single unauthenticated GET to /api/v1/retrieval/ leaks Open WebUI's full RAG pipeline config — chunk sizes, templates, embedding and reranking mo...

CTF - Time is but a Window
Writeup of the Time is but a Window binary exploitation CTF challenge

CTF - A Guilded Lily
Writeup of the A Guilded Lily binary exploitation CTF challenge

CTF - My Friend, A Loathsome Worm
Writeup of the My Friend, A Loathsome Worm binary exploitation CTF challenge

HTB - Sau
Walkthrough of the Sau machine from Hack The Box

HTB - Space Pirate: Going Deeper
Walkthrough of the Space Pirate: Going Deeper binary exploitation challenge from Hack The Box

HTB - Cybermonday
Walkthrough of the Cybermonday machine from Hack The Box

HTB - Pilgrimage
Walkthrough of the Pilgrimage machine from Hack The Box

HTB - Broker
Walkthrough of the Broker machine from Hack The Box

HTB - Topology
Walkthrough of the Topology machine from Hack The Box

Oracle Content Management (CMS) - One Click Account Takeover
A CORS misconfiguration in Oracle Content Management leads to massive CSRF which can turn into one-click account takeover
No writeups in this category yet.