websocket-security

2 articles
sort: new top best
clear filter
0 3/10

Researcher found a chain of vulnerabilities in Legal Robot: HTML injection leading to open redirect via META refresh tags, combined with a misconfigured WebSocket Origin header allowing CSRF attacks from different origins. The vulnerability chain required no XSS execution due to CSP but achieved account logout and malicious script execution through forced redirects.

Legal Robot HackerOne Armaan Pathan
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 4/10

Opinion piece critiquing Meta's acquisition of Moltbook and OpenAI's hiring of OpenClaw creator Peter Steinberger, highlighting severe security vulnerabilities in both platforms including unauthenticated database access, remote code execution (CVE-2026-25253), secret key exposure, and malware in the OpenClaw skills marketplace.

Moltbook OpenClaw Meta OpenAI Peter Steinberger CVE-2026-25253 Gal Nagli Wiz Supabase NanoClaw TrustClaw Carapace AI The Colony Clawstr 4Claw Kevin Breen Immersive
zdnet.com · CrankyBear · 1 day ago · details · hn