One Byte Of Disagreement
How we use Codex to find vulnerabilities worked end to end on GHSA-f8fg-pg57-v4j8 XSS in league/commonmark's AttributesExtension: the on* event-handler filter bypassed with a single form feed I. Intro

Search for a command to run...
Series
Data goes in. Exploits come out.
How we use Codex to find vulnerabilities worked end to end on GHSA-f8fg-pg57-v4j8 XSS in league/commonmark's AttributesExtension: the on* event-handler filter bypassed with a single form feed I. Intro

How I used Codex to find CVE-2026-58444 in Gitea A token-scope enforcement bypass on GET /{owner}/{repo} GHSA-cp3q-vrj2-ghhh I. Introduction Gitea is an open-source, self-hostable Git service the "Git

How we use Codex to find vulnerabilities worked end to end on CVE-2026-59992 Broken access control in next-tinacms-s3 and its three sibling media adapters GHSA-8mq9-5fw2-5rm4 I. Introduction TinaCMS i

I. Introduction Coolify is an open-source, self-hostable PaaS that lets you deploy apps, databases, and pre-baked services on your own servers — the "Vercel/Heroku/Netlify replacement, but you own the

I. Introduction Kestra is an open-source event-driven workflow orchestration platform written in Java on top of Micronaut. It lets teams declare "flows" — task graphs that move data, call APIs, run sc

Disclosure status: Reported to vendor and coordinated through a private fix path. I. Introduction Warp is an agentic development environment, born out of the terminal. Use Warp's built-in coding agent
![[CVE-2026-48731] AI-Assisted Discovery of Command Injection in Warp Terminal](https://cdn.hashnode.com/uploads/covers/699fec8cc9015c37f6e5364f/e7817cef-a8af-45ec-b931-4e08225edeb6.png)