CVE-2026-5917: OS Command Injection in libgit2’s SSH Backend
libgit2’s libssh2 backend quotes the repository path but escapes nothing. One quote in the path can run commands on an SSH server that gives a shell.
Read637th Research Lab
libgit2’s libssh2 backend quotes the repository path but escapes nothing. One quote in the path can run commands on an SSH server that gives a shell.
ReadA malicious broker splits one PUBLISH across two TCP segments, skips a bounds check that is present and correct, and overwrites a function pointer.
ReadASUSTOR Backup Plan’s Windows service ABP_VSS_Service treats encryption as authentication and checks paths with a substring test. Standard user to SYSTEM.
ReadThree CVEs in U-Boot’s network stack: a TCP integer underflow that corrupts packet processing and an NFS path overflow that escapes a 2048-byte buffer.
ReadFour CVEs in barebox: an unbounded DHCP option scan, two ext4 parsing flaws, and a PE virtual-size integer overflow in the EFI loader.
ReadA SYSTEM service applies unsigned .ppkg packages from a folder — no signature, no consent. Microsoft’s docs promise otherwise. Honest catch: admin→SYSTEM.
ReadBuilding an AI that reverse-engineers undocumented Windows internals and raises its own hypotheses. The method, the rig, and the limit it has not crossed.
ReadHow the AI workflow that found a strongSwan zero-day discovered a 9-year-old heap overflow in BusyBox’s DHCPv6 client, plus a full PoC walkthrough.
ReadHow I discovered CVE-2026-25075, a bug hiding in strongSwan since 2011, using a structured multi-pass AI analysis workflow.
Readlibgit2’s libssh2 backend quotes the repository path but escapes nothing. One quote in the path can run commands on an SSH server that gives a shell.
A malicious broker splits one PUBLISH across two TCP segments, skips a bounds check that is present and correct, and overwrites a function pointer.
ASUSTOR Backup Plan’s Windows service ABP_VSS_Service treats encryption as authentication and checks paths with a substring test. Standard user to SYSTEM.
Three CVEs in U-Boot’s network stack: a TCP integer underflow that corrupts packet processing and an NFS path overflow that escapes a 2048-byte buffer.