Policy bypass via a client-controlled X-Original-URI header
A client-controlled header was trusted before the request path, allowing matching ALLOW rules to bypass the Anubis challenge.
vulnerability research
Published vulnerabilities from my security research.
Additional findings are moving through coordinated disclosure.
Web AI firewall · 1 CVE
A client-controlled header was trusted before the request path, allowing matching ALLOW rules to bypass the Anubis challenge.
AI-native database · 6 CVEs
An unauthenticated attacker could submit a malicious model repository with trust_remote_code enabled and execute code on the server.
A user with collection-update permission could load a malicious model repository with trust_remote_code and execute code on the server.
Any authenticated user could read, write, update, or delete collections belonging to another tenant.
Any authenticated user could read, write, update, or delete collections belonging to another tenant.
The provider checked whether a user held a permission, but not which tenant, database, or collection that permission applied to.
The V1 endpoints passed no tenant or database to the authorization layer, allowing its controls to be bypassed.
NLP framework · 1 CVE
Loading a malicious language model could trigger unsafe deserialization and execute arbitrary code.
Threat intelligence platform · 1 CVE
A site administrator could traverse outside the intended path when viewing an EventReport picture.
Deep-learning framework · 1 CVE
A malicious Keras file could execute arbitrary code when loaded, despite safe mode being enabled.
AI compute platform · 3 CVEs
An attacker could take over active sessions and access, steal, or alter data available inside them.
Unauthenticated users could create accounts and reach private data even when registration was disabled.
Sensitive data exposed through active sessions could reveal management-platform credentials.
Scores shown are CNA-provided base scores from the linked CVE records.