Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

moltenbit

@moltenbit@infosec.exchange
  • Open on infosec.exchange

Security researcher. Bug bounty hunter. Finding vulnerabilities. Occasionally writing about it at moltenbit.net

0 Followers
0 Following
3 Posts
Joined June 27, 2024
blog:
https://moltenbit.net
bluesky:
https://bsky.app/profile/moltenbit.bsky.social

Posts

Open post
moltenbit
moltenbit @moltenbit@infosec.exchange · Jul 31, 2026
moltenbit
@moltenbit@infosec.exchange

Security researcher. Bug bounty hunter. Finding vulnerabilities. Occasionally writing about it at moltenbit.net

infosec.exchange
two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there. CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94. CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93. https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj #GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
0
0
0
0
Open post
moltenbit
moltenbit @moltenbit@infosec.exchange · Jul 23, 2026
moltenbit
@moltenbit@infosec.exchange

Security researcher. Bug bounty hunter. Finding vulnerabilities. Occasionally writing about it at moltenbit.net

infosec.exchange
new writeup: three bugs in vinext's alpha, cloudflare's next.js reimplementation that one engineer built with an AI model in about a week for roughly $1,100 in tokens. the good one: vinext checks middleware matchers against the path with the i18n locale prefix still on it, then strips the locale when it resolves the route. /fr/dashboard misses /dashboard/:path*, the auth middleware never runs, and the router serves /dashboard anyway. also a middleware header allowlist that is really a merge, and reflected XSS via unescaped attribute names in the next/head serializer. reported in february, cloudflare fixed all three. https://moltenbit.net/posts/three-bugs-in-cloudflares-vinext-alpha/ #infosec #appsec #cloudflare #nextjs #bugbounty #cybersecurity #security
0
0
0
0
Open post
moltenbit
moltenbit @moltenbit@infosec.exchange · Jun 30, 2026
moltenbit
@moltenbit@infosec.exchange

Security researcher. Bug bounty hunter. Finding vulnerabilities. Occasionally writing about it at moltenbit.net

infosec.exchange
RE: https://infosec.exchange/@moltenbit/116608526922719220 Writeup is online: https://moltenbit.net/posts/auditing-openreception/ #cybersecurity #vulnerability #infosec #security
0
0
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:59:32 UTC