Inside the mindset and craft of open-source zero-day research dead ends, silent assumptions, patch archaeology, and the one wrong function name that kept CVE-2026-32808 alive.
Write-ups and analysis
7 pieces. Where a piece was published elsewhere its link goes to the original, which remains the canonical copy - this page indexes that work, it does not republish it.
Advisory write-ups
Vulnerability write-up
The Alias Was Ours. The Target Wasn't: CVE-2025-13437 in google/zx
How setup created a temporary node_modules link, teardown remembered its resolved target, and an ownership mistake turned cleanup into recursive deletion outside the working tree
Vulnerability write-up
CVE-2026-70622 - tar-rs `Builder::append_dir_all` symlink escape allows privileged out-of-root file disclosure
Advisory and reproduction for a symlink escape in tar-rs archive construction that lets a file outside the intended root be read into the archive.
Two handling flaws in the LiME kernel memory acquisition module: RAM disclosure over an unauthenticated TCP listener, and disk dumps created world-readable by default.
Vulnerability write-up
CVE-2026-61371 - Microsoft AVML symlink following on destination output open (CWE-59)
Symlink following when AVML opens its destination output path, allowing a write to be redirected outside the intended location.
Vulnerability write-up
CVE-2025-59716 - ownCloud Guests pending-user enumeration via registration endpoint
The ownCloud Guests registration endpoint distinguishes pending users, allowing account enumeration.
Vulnerability write-up
PoC for Incorrect Access Control in @digitalocean/do-markdownit (≤1.16.1) - includes console and web demo exploits.
Proof of concept for an allow-list bypass in DigitalOcean's do-markdownit, with console and web reproductions.