$ whoami
novice-22
CTF Team : RubiyaLab |CTF 소그룹 : RubiyaLab Holiday (Group Lead)
전체 0 오늘 0
최근 글
001
주요통신기반시설
CI · 코드 인젝션
/auth/ldap-login, /admin/tools/ping, /board/free/write, /auth/xml-login, /api/v1/xml-import, /misc/preview
002
취약점 제보
CVE-2026-18482 : neo.mjs
OS command injection in the neo.mjs file-system MCP server (check_syntax / run_playwright_test)
003
취약점 제보
kubeshark — CWE-22
MCP download_file writes fetched bytes to an unvalidated destination path
004
취약점 제보
kubeshark — CWE-88
MCP start_kubeshark argument injection allows redirecting deployed images to an attacker-controlled registry
005
취약점 제보
nginx-ui — CWE-494
Self-upgrade runs an unsigned binary verified only by a same-origin digest (CWE-494) → RCE via a compromised mirror or MITM