AJAmartya Jhainsecurity-research.hashnode.dev·1h ago · 8 min readDissecting FOIS: The Log4j2 Filter That Only Does Half Its JobTL;DR Log4j2's FilteredObjectInputStream (FOIS) checks the class names in a serialized stream and nothing else. It never limits object size or depth. That one gap gives three problems on a single ne00
AJAmartya Jhainsecurity-research.hashnode.dev·23h ago · 10 min readHow a GitHub Triage Role Hijacked an Already-Authorized Claude Code Action RunHackerOne #3918594 · Claude Code Action v1.0.185, commit 9db594c7a0e82298c121c18b7f08aa1579ce7341 · CVSS 4.0 score 7.5, High Authorizing an automated job is really two promises: who gets to start it,00
AJAmartya Jhainsecurity-research.hashnode.dev·23h ago · 10 min readEscaping Claude Code's Sandbox: A TOCTOU Bug That Let Repo Code Overwrite Host FilesHackerOne #3882177 · Claude Code 2.1.217, macOS arm64 · CVSS 4.0 score 7.7, High Sandboxing runs on a simple promise: code inside it cannot reach outside it. Claude Code, Anthropic's coding agent, ke00
AJAmartya Jhainsecurity-research.hashnode.dev·6d ago · 5 min readCVE-2026-71511 · Read a member's card, receive their password hashCVSS 6.5 · Sensitive data exposure (CWE-200) · Fixed in Dolibarr 24.0.0 Every reply is supposed to pass a redactor that blacks out secrets. The Users redactor blacks out the password. The Members reda00
AJAmartya Jhainsecurity-research.hashnode.dev·6d ago · 6 min readCVE-2026-71510 · Ask enough yes/no questions and you know everyone's salaryCVSS 6.5 · Authorization oracle → blind disclosure (CWE-863 / CWE-200) · Fixed in Dolibarr 24.0.0 You can't see the salary column, but the search box will happily answer “is this person's salary above00