Results for "Python"
- Article
Business Logic Is AppSec’s Unsolved Problem
Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the g…
- Article
Why Static Analysis Struggles with Business Logic Vulnerabilities
The gap between tracking where data flows and reasoning about whether the logic is correct.
- Article
CVE-2025-51479: ONYX Authorization Bypass in Enterprise Edition Group Management API
Authorization bypass vulnerability in ONYX Enterprise Edition allowing curators to manipulate groups outside their authorized scope.
- Article
CVE-2025-51458: DB-GPT SQLI via CVE Bypass (CVE-2024-10835 & CVE-2024-10901)
SQL injection vulnerability in DB-GPT 0.7.0 despite fixes for prior CVEs, affecting multiple database endpoints.
- Article
CVE-2025-51462: Ragflow XSS in Dialog Configuration
Stored cross-site scripting vulnerability in Ragflow’s dialog configuration functionality allowing malicious HTML/JavaScript execution.
- Article
CVE-2025-51463: Aim Path Traversal in Server Backup Restoration
A path traversal vulnerability was found in AIM server. This vulnerability allows remote attackers to write arbitrary files on the server’s filesystem via a mal…
- Article
CVE-2025-51472: SuperAGI RCE via Unsafe Eval in Template Config
Remote code execution vulnerability in SuperAGI through unsafe eval() usage in agent template configuration processing.
- Article
CVE-2025-51475: SuperAGI AFO in File Upload Endpoint
Arbitrary file overwrite vulnerability in SuperAGI’s file upload functionality due to insufficient path sanitization.
Showing 11 - 18 of 18 results