<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cipher Research</title><description>Attack chain anatomy, methodology deep dives, and security research from the team building Cipher.</description><link>https://causalsecurity.com/</link><language>en-us</language><item><title>Eight vulnerabilities in BusyBox</title><link>https://causalsecurity.com/research/busybox-security-research/</link><guid isPermaLink="true">https://causalsecurity.com/research/busybox-security-research/</guid><description>Cipher found eight vulnerabilities in BusyBox. The most serious lets an unauthenticated client crash the TLS server on the first handshake message. Others overflow the heap from a crafted filesystem image and accept a stored password hash as the password.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>memory-safety</category></item><item><title>An authenticated peer stalls an IKEv2 rekey and drives strongSwan through freed memory</title><link>https://causalsecurity.com/research/strongswan-ikev2-rekey-collision-uaf/</link><guid isPermaLink="true">https://causalsecurity.com/research/strongswan-ikev2-rekey-collision-uaf/</guid><description>strongSwan&apos;s IKEv2 rekey-collision handling caches a raw pointer to a task it does not own. An authenticated peer can make the task manager free that task, then deliver a delayed response that dereferences the dangling pointer for an indirect call.</description><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>memory-safety</category></item><item><title>A zero-privilege OpenMRS account could still read patient observations over FHIR</title><link>https://causalsecurity.com/research/openmrs-fhir2-override-authz-bypass/</link><guid isPermaLink="true">https://causalsecurity.com/research/openmrs-fhir2-override-authz-bypass/</guid><description>FHIR2 declares its read privileges as annotations on DAO interfaces. Where a concrete class overrides one of those methods, the annotation lookup lands on the override, which carries none, and the privilege check is skipped.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>business-logic</category></item><item><title>One Router Advertisement on the local link drives an unbounded write in Zephyr</title><link>https://causalsecurity.com/research/zephyr-6lowpan-context-unbounded-write/</link><guid isPermaLink="true">https://causalsecurity.com/research/zephyr-6lowpan-context-unbounded-write/</guid><description>Zephyr&apos;s IPv6 stack takes an 8-bit context length straight from a Router Advertisement and never bounds it to the RFC&apos;s 128. One packet from any on-link host underflows a memset length and zeroes memory far past a 16-byte buffer.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>memory-safety</category></item><item><title>From a nurse-level login to full database extraction in OpenEMR</title><link>https://causalsecurity.com/research/openemr-fee-sheet-sql-injection/</link><guid isPermaLink="true">https://causalsecurity.com/research/openemr-fee-sheet-sql-injection/</guid><description>OpenEMR&apos;s Fee Sheet inventory query uses bind parameters for its values, but the sort target, which a parameter can&apos;t fill, is built from a request field by string interpolation. A low-privileged clinical user injects there and reads the whole database, including password hashes.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category></item><item><title>From one visited web page to remote code execution in Eclipse Theia</title><link>https://causalsecurity.com/research/eclipse-theia-file-upload-csrf/</link><guid isPermaLink="true">https://causalsecurity.com/research/eclipse-theia-file-upload-csrf/</guid><description>Eclipse Theia&apos;s browser backend enforces its connection token only on the WebSocket upgrade, leaving every HTTP route open. A page the victim merely visits can POST to /file-upload and write files anywhere the backend can reach, up to code execution on the host.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>business-logic</category></item><item><title>IPv6 translation reaches ACL-blocked internal destinations through coturn</title><link>https://causalsecurity.com/research/coturn-peer-acl-encoding-bypass/</link><guid isPermaLink="true">https://causalsecurity.com/research/coturn-peer-acl-encoding-bypass/</guid><description>coturn&apos;s denied-peer-ip list recognized one way of writing an IPv4 address inside an IPv6 address. Written any of the other ways, the same denied destination passed the check and the relay connected to it.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>business-logic</category></item><item><title>Hidden rows, exposed values: inference through Hasura&apos;s computed-field filters</title><link>https://causalsecurity.com/research/hasura-computed-field-authz-bypass/</link><guid isPermaLink="true">https://causalsecurity.com/research/hasura-computed-field-authz-bypass/</guid><description>A Hasura computed field returning SETOF a table inherits that table&apos;s row permissions on selection, relationships, and aggregations. On one path, a where-clause over the field, the filter is dropped, turning it into a boolean oracle for hidden rows.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>business-logic</category></item><item><title>From tenant database owner to OS command execution in StackGres</title><link>https://causalsecurity.com/research/stackgres-metrics-exporter-rce/</link><guid isPermaLink="true">https://causalsecurity.com/research/stackgres-metrics-exporter-rce/</guid><description>StackGres&apos;s bundled metrics exporter opens superuser sessions into every tenant database and runs unqualified catalog SQL with no search_path pinning, so a tenant database owner can shadow a function and reach OS command execution in the primary Postgres pod.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>business-logic</category></item><item><title>Just listing a crafted ext2/3/4 image triggers a heap over-read in 7-Zip</title><link>https://causalsecurity.com/research/sevenzip-ext-oob-read/</link><guid isPermaLink="true">https://causalsecurity.com/research/sevenzip-ext-oob-read/</guid><description>7-Zip parses ext2/3/4 disk images by content. One attacker-controlled superblock field drives the inode-bitmap scan past a fixed-size buffer: a heap out-of-bounds read that crashes the process the moment an untrusted image is listed or extracted.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>memory-safety</category></item><item><title>Supabase Realtime delivered presence updates despite an explicit read denial</title><link>https://causalsecurity.com/research/supabase-realtime-presence-leak/</link><guid isPermaLink="true">https://causalsecurity.com/research/supabase-realtime-presence-leak/</guid><description>Supabase Realtime enforces a presence.read policy on the initial presence snapshot but not on the ongoing presence_diff fan-out, so a member allowed to broadcast but denied presence can still read every other member&apos;s presence metadata on a private channel.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>business-logic</category></item><item><title>A two-decade-old heap overflow in GraphicsMagick&apos;s PCD decoder</title><link>https://causalsecurity.com/research/graphicsmagick-pcd-write-overflow/</link><guid isPermaLink="true">https://causalsecurity.com/research/graphicsmagick-pcd-write-overflow/</guid><description>GraphicsMagick ported ImageMagick&apos;s out-of-bounds read fix for the PCD decoder but not the write-side bound that shipped alongside it, leaving an attacker-controlled heap overflow in DecodeImage: the un-ported other half of the same hardening.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>memory-safety</category></item><item><title>Minting wallet money from the open internet</title><link>https://causalsecurity.com/research/wallet-mint-open-internet/</link><guid isPermaLink="true">https://causalsecurity.com/research/wallet-mint-open-internet/</guid><description>A consumer fintech asked Cipher to extend a review into its infrastructure. Modeling the wallet&apos;s request flow end to end surfaced an internal money-crediting endpoint reachable, unauthenticated, from the open internet (proven with a reverted credit).</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>case-study</category><category>business-logic</category><category>payment-flows</category></item><item><title>ZITADEL let one OAuth client redeem codes and tokens issued to another</title><link>https://causalsecurity.com/research/zitadel-oauth-client-binding/</link><guid isPermaLink="true">https://causalsecurity.com/research/zitadel-oauth-client-binding/</guid><description>ZITADEL&apos;s OAuth token endpoint authenticated the calling client but never checked that the grant it was redeeming had been issued to that client. The same binding check already existed on the revoke path. One missing invariant, spanning three grant types and token exchange.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>business-logic</category></item><item><title>Seven vulnerabilities in Vim, from crashes to code execution</title><link>https://causalsecurity.com/research/vim-security-research/</link><guid isPermaLink="true">https://causalsecurity.com/research/vim-security-research/</guid><description>Seven memory-safety and code-execution flaws Cipher reported in Vim, from spell-file and soundfold crashes to command injection in netrw and arbitrary code execution in C omni-completion. All fixed upstream; one had sat in the spell code since 2006.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>open-source</category><category>memory-safety</category></item><item><title>One unauthenticated NAS message triggers an out-of-bounds read in Open5GS&apos;s 5G core</title><link>https://causalsecurity.com/research/open5gs-amf-nas-oob-read/</link><guid isPermaLink="true">https://causalsecurity.com/research/open5gs-amf-nas-oob-read/</guid><description>Cipher reported a pre-authentication out-of-bounds read in Open5GS, the open-source 5G core. One malformed NAS message reaches the AMF before authentication and crashes it, taking service down for every connected subscriber.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>disclosure</category><category>memory-safety</category><category>open-source</category></item><item><title>One auth flaw to full payout control: chaining five bugs in a payments platform</title><link>https://causalsecurity.com/research/payments-platform-takeover-chain/</link><guid isPermaLink="true">https://causalsecurity.com/research/payments-platform-takeover-chain/</guid><description>A field report from a cross-border payments engagement. Five findings, each a routine medium on its own, chain from an anonymous Internet request to direct money movement. The work was reading them together.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>case-study</category><category>payment-flows</category><category>business-logic</category></item></channel></rss>