Cc0wkinginblogs.night-wolf.io·4d ago · 17 min readFrom Graph Editor to Webshell: Finishing the Job CVE-2026-40079 Left OpenMost advisories end with "fixed." This one ended with a sentence that read like an open invitation: Status: PARTIALLY FIXED. The tune function is fixed. The graph rendering shell_exec path has residu00
Cc0wkinginblogs.night-wolf.io·4d ago · 10 min readA Certificate Name That Runs as Root: Five Bugs in Sophos Firewall, Found with CodexA firewall appliance is one of those boxes where the job description and the threat model are the same sentence. It sits at the edge of the network, it terminates the VPN, it holds the credentials for00
Cc0wkinginblogs.night-wolf.io·Jun 8 · 7 min read[CVE-2026-48731] AI-Assisted Discovery of Command Injection in Warp TerminalDisclosure status: Reported to vendor and coordinated through a private fix path. I. Introduction Warp is an agentic development environment, born out of the terminal. Use Warp's built-in coding agent10
Cc0wkinginblogs.night-wolf.io·May 17 · 5 min read[CVE-2026-34612] AI-Assisted Discovery of SQL Injection Leading to RCE in Kestra v1.3.2I. Introduction Kestra is an open-source tool that helps automate and manage workflows. It allows users to create and run workflows on a schedule or when an event occurs. With Kestra, users can easily30
Cc0wkinginc0wking.hashnode.dev·Apr 3 · 1 min readStored-XSS in ERPNext (Frappe) Email Template EngineI. Description The Email Template engine is vulnerable to Cross-Site Scripting (XSS).An attacker with permission to create or edit email templates can inject malicious javascript code that are execute00