VPVũ Phúc Thànhinblogs.night-wolf.io·Sep 11 · 18 min readOne Byte Of DisagreementHow we use Codex to find vulnerabilities worked end to end on GHSA-f8fg-pg57-v4j8 XSS in league/commonmark's AttributesExtension: the on* event-handler filter bypassed with a single form feed I. Intro00
VPVũ Phúc Thànhinblogs.night-wolf.io·Sep 11 · 13 min readOne Route The Patch ForgotHow I used Codex to find CVE-2026-58444 in Gitea A token-scope enforcement bypass on GET /{owner}/{repo} GHSA-cp3q-vrj2-ghhh I. Introduction Gitea is an open-source, self-hostable Git service the "Git00
VPVũ Phúc Thànhinblogs.night-wolf.io·Sep 11 · 19 min readmediaRoot Was Not A WallHow we use Codex to find vulnerabilities worked end to end on CVE-2026-59992 Broken access control in next-tinacms-s3 and its three sibling media adapters GHSA-8mq9-5fw2-5rm4 I. Introduction TinaCMS i00
VPVũ Phúc Thànhinblogs.night-wolf.io·Jun 16 · 10 min readDeleting any file on a Coolify managed server with a single `..`I. Introduction Coolify is an open-source, self-hostable PaaS that lets you deploy apps, databases, and pre-baked services on your own servers — the "Vercel/Heroku/Netlify replacement, but you own the00
VPVũ Phúc Thànhinblogs.night-wolf.io·Jun 16 · 14 min readBypassing Kestra's path-traversal guard with a single backslashI. Introduction Kestra is an open-source event-driven workflow orchestration platform written in Java on top of Micronaut. It lets teams declare "flows" — task graphs that move data, call APIs, run sc00