moltenbit

I break software before someone worse does.

Security research and bug bounty, done the boring way: reported to the vendor, fixed, then written up here.

Latest writeups / 3

all writeups →

From the ledger / 5 of 34

full ledger →
No CVE
vinext

Authentication bypass via i18n locale prefix; middleware matcher evaluates unsanitized pathname

No CVE
vinext

Middleware header sanitization bypass; missing x-middleware-override-headers allows header spoofing

No CVE
vinext

Reflected XSS via unescaped attribute names in next/head SSR serializer

CVE-2026-65825
OpenReception

one tenant’s throttle row disables the PIN brute-force throttle for the same identifier in other tenants

CVE-2026-65824
OpenReception

invite confirmation token is replayable within its validity window and re-issues a registration-bootstrap cookie