moltenbit

I break software before someone worse does.

Security research and bug bounty, done the boring way: reported to the vendor, fixed, then written up here.

Latest writeups / 3

all writeups →

From the ledger / 5 of 36

full ledger →
CVE-2026-46647
GlobaLeaks

insufficient role enforcement allows non-admin internal users on the root or management tenant to read and modify network configuration

CVE-2026-46648
GlobaLeaks

incomplete tenant scoping lets a non-root tenant admin clear secondary escrow backup keys across all tenants

No CVE
vinext

Authentication bypass via i18n locale prefix; middleware matcher evaluates unsanitized pathname

No CVE
vinext

Middleware header sanitization bypass; missing x-middleware-override-headers allows header spoofing

No CVE
vinext

Reflected XSS via unescaped attribute names in next/head SSR serializer