Aaivr-bloginaivr.hashnode.dev·1h ago · 2 min readWebmin Help Template Authenticated Remote Command ExecutionSummary Webmin help system accepts template variables via query parameters and processes them through the eval function. This allows an authenticated user to execute commands with root privileges. How00
Aaivr-bloginaivr.hashnode.dev·Jan 26 · 21 min readFinding 0days with AIFor decades, many bug hunters and security pros have used manual testing, static analysis, and fuzzing to find vulnerabilities. Enter the age of AI. Many are skeptical, but when I look around I see mo00
Aaivr-bloginaivr.hashnode.dev·Jan 23 · 3 min readAwesomeBot meets MCPIntro AwesomeBot is an awesome AI Chatbot! It was vibe coded from scratch to have a ton of awesome features without much security in mind so various attacks and offensive methods can be demonstrated. Today, AwesomeBot meets MCP. What happens next? Le...00
Aaivr-bloginaivr.hashnode.dev·Jan 14 · 7 min readAwesomeBot meets Prompt InjectionIntro AwesomeBot is an awesome AI Chatbot! It was vibe coded from scratch to have a ton of awesome features without much security in mind so various attacks and offensive methods can be demonstrated. This series of blog posts serves as a way to under...00
Aaivr-bloginaivr.hashnode.dev·Jan 10 · 4 min readLibreChat MCP Stdio Remote Command ExecutionSummary LibreChat's Model Context Protocol (MCP) implementation contained a critical vulnerability (CVE-2026-22252) that allowed any authenticated user to gain root-level remote code execution (RCE) within the Docker container. A single API request c...00