Incus
CVE-2026-81494
From project-boundary escape to root command execution
A critical trust-boundary vulnerability chained with arbitrary host-file overwrite to demonstrate root command execution.
Offensive security · Application security · Vulnerability research
I investigate trust boundaries, source code, and memory-safety failures. My work includes three publicly credited CVE discoveries and a Critical CVSS 9.6 Incus chain demonstrated through root command execution.
CVE-2026-81494
From project-boundary escape to root command execution
A critical trust-boundary vulnerability chained with arbitrary host-file overwrite to demonstrate root command execution.
CVE-2026-68546
Heap out-of-bounds write
C++ memory-safety flaw in RemoteIo processing of URL-based resources.
CVE-2026-84448
Heap out-of-bounds read
Insufficient validation in inline-mask region handling, reproduced with AddressSanitizer.
A security-analysis framework combining static analysis, reverse engineering, threat intelligence, and ML-assisted triage to support analysts.
Runtime-aware analysis for native, .NET, and PyInstaller artifacts; Python, Ghidra, SHAP, and Docker.
Explore the frameworkReproduction of CVE-2024-36039, an object-key serialization flaw leading to SQL injection. A Docker lab, reproducible PoC, and technical analysis.
Reproduction and analysis of an existing CVE; not an original vulnerability discovery.
View the PoC & analysisHands-on vulnerability research and CVE reproduction in controlled labs, analyzing root causes, exploitation conditions, and security impact.
Technical write-ups across reverse engineering, web security, digital forensics, pwn, and cryptography.
Read the challenge write-upsMình tham gia cuộc thi này cuối năm 2025, một phần cũng bận và hơi lười nên đến bây giờ mới có thời gian viết lại writeup. Một số challenge mình viết bằ...
“Bảo mật Smart Contract không chỉ dừng lại ở việc viết code đúng cú pháp (syntax), mà nằm ở việc thấu hiểu tường tận cách máy ảo Ethereum (EVM) vận hành...
Dưới đây là lời giải chi tiết cho các bài CTF mình đã clear thành công. Mỗi bài viết là một trải nghiệm và những kiến thức mới mà mình đã đúc kết được.
For conversations about offensive security, application security, and vulnerability research.
More about me