⤷ Title: Prototype Pollution — a JavaScript Vulnerability
════════════════════════
𐀪 Author: appsecwarrior
════════════════════════
ⴵ Time: Sat, 16 Aug 2025 14:52:58 GMT
════════════════════════
⌗ Tags: #security #hacking #penetration_testing #prototype_pollution #bug_bounty
════════════════════════
𐀪 Author: appsecwarrior
════════════════════════
ⴵ Time: Sat, 16 Aug 2025 14:52:58 GMT
════════════════════════
⌗ Tags: #security #hacking #penetration_testing #prototype_pollution #bug_bounty
Medium
Prototype Pollution — a JavaScript Vulnerability
Prototype Pollution is a security vulnerability that affects JavaScript applications, particularly those using objects and inheritance. It…
⤷ Title: Prototype Pollution in Pentesting — (Part 1)
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Fri, 19 Sep 2025 03:00:39 GMT
════════════════════════
⌗ Tags: #prototype_pollution #javascript #web_application_security #ethical_hacking #web_app_pentesting
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Fri, 19 Sep 2025 03:00:39 GMT
════════════════════════
⌗ Tags: #prototype_pollution #javascript #web_application_security #ethical_hacking #web_app_pentesting
Medium
Prototype Pollution in Pentesting — (Part 1)
Prototype pollution is typically a JavaScript-specific vulnerability where an attacker is able to inject or modify properties on an…
⤷ Title: Prototype Pollution in Pentesting — (Part 2)
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 03:03:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking #prototype_pollution #javascript #web_app_pentesting #web_vulnerabiltiies
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 03:03:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking #prototype_pollution #javascript #web_app_pentesting #web_vulnerabiltiies
Medium
Prototype Pollution in Pentesting — (Part 2)
Read Part 1 here.
⤷ Title: Prototype Pollution Masterclass: Practical Exploits, Detection & Node.js RCE
════════════════════════
𐀪 Author: PyUs3r
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 00:00:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #prototype_pollution #web_security #nodejs
════════════════════════
𐀪 Author: PyUs3r
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 00:00:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #prototype_pollution #web_security #nodejs
Medium
Prototype Pollution Masterclass: Practical Exploits, Detection & Node.js RCE
Complete, hands-on guide to Prototype Pollution. Client & server exploitation, jQuery/hash vectors, DOM XSS, Node.js RCE for bug bounty.
⤷ Title: CyCTF25: I Hate Tasks Official Writeup
════════════════════════
𐀪 Author: Abdelnour Osman (DarkT)
════════════════════════
ⴵ Time: Sat, 08 Nov 2025 21:15:19 GMT
════════════════════════
⌗ Tags: #web_exploitation #ctf_writeup #prototype_pollution #capture_the_flag #cybersecurity
════════════════════════
𐀪 Author: Abdelnour Osman (DarkT)
════════════════════════
ⴵ Time: Sat, 08 Nov 2025 21:15:19 GMT
════════════════════════
⌗ Tags: #web_exploitation #ctf_writeup #prototype_pollution #capture_the_flag #cybersecurity
Medium
CyCTF25: I Hate Tasks Official Writeup
I Hate Tasks — a Node.js/Express web application using SQLite for persistence. The application allows users to create tasks and mark them…
⤷ Title: “RondoDoX” Strikes Back: Exposed Logs Reveal Massive 9-Month Campaign Targeting Next.js and IoT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 02:33:19 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CloudSEK #CVE_2025_55182 #IoT security #Next.js #Prototype Pollution #rce #React2Shell #RondoDox #Server Actions #Web Framework Security #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 02:33:19 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CloudSEK #CVE_2025_55182 #IoT security #Next.js #Prototype Pollution #rce #React2Shell #RondoDox #Server Actions #Web Framework Security #XMRig
Daily CyberSecurity
“RondoDoX” Strikes Back: Exposed Logs Reveal Massive 9-Month Campaign Targeting Next.js and IoT
The RondoDoX botnet has resurfaced with a potent new arsenal, shifting its sights from simple routers to enterprise-grade web frameworks. A new intelligence report from CloudSEK details a sprawlin…
⤷ Title: Prototype Pollution → Template Injection → RCE The Vulnerable Node Lab That Finally Made It Click
════════════════════════
𐀪 Author: ParadoxYab
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 09:03:44 GMT
════════════════════════
⌗ Tags: #rce #ssti #prototype_pollution #web_hacking #cybersecurity
════════════════════════
𐀪 Author: ParadoxYab
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 09:03:44 GMT
════════════════════════
⌗ Tags: #rce #ssti #prototype_pollution #web_hacking #cybersecurity
Medium
Prototype Pollution → Template Injection → RCE The Vulnerable Node Lab That Finally Made It Click
Prototype Pollution was one of those vulnerabilities that I kept seeing in CVEs, blogs, and conference slides… but never felt like I truly…
⤷ Title: Menemukan Kerentanan Prototype Pollution di Absensi Pemerintahan: Lessons Learned dari Penetration…
════════════════════════
𐀪 Author: Ahmadfaizabdillah
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 11:27:49 GMT
════════════════════════
⌗ Tags: #hacking #cve #vulnerability #prototype_pollution #bug_hunting
════════════════════════
𐀪 Author: Ahmadfaizabdillah
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 11:27:49 GMT
════════════════════════
⌗ Tags: #hacking #cve #vulnerability #prototype_pollution #bug_hunting
Medium
Menemukan Kerentanan Prototype Pollution di Absensi Pemerintahan: Lessons Learned dari Penetration…
Selama penetration testing terhadap sistem absensi pemerintah daerah, saya menemukan kerentanan kritis CVE-2019–11358 (Prototype Pollution)…
⤷ Title: HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
Daily CyberSecurity
HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
A high-severity vulnerability has been discovered in Axios, the immensely popular HTTP client used by millions of developers for Node.js and browser-based applications. The flaw, tracked as CVE-20…
⤷ Title: Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Taint Bypass #CVE_2026_25881 #JavaScript Security #Patch Alert #Prototype Pollution #Remote Code Execution #Sandbox Escape #SandboxJS #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Taint Bypass #CVE_2026_25881 #JavaScript Security #Patch Alert #Prototype Pollution #Remote Code Execution #Sandbox Escape #SandboxJS #Web Security
Daily CyberSecurity
Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover
Critical SandboxJS flaw CVE-2026-25881 allows sandbox escape via prototype pollution. Malicious code can modify host logic & execute RCE. Update to v0.8.31.
⤷ Title: CVE-2026-27212: Critical Swiper Prototype Pollution Flaw (CVSS 9.4) Exposes Global Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:12:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AppSec #CVE_2026_27212 #Cyber Security #infosec #JavaScript Security #npm Vulnerability #Patch Alert #Prototype Pollution #Remote Code Execution #Swiper
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:12:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AppSec #CVE_2026_27212 #Cyber Security #infosec #JavaScript Security #npm Vulnerability #Patch Alert #Prototype Pollution #Remote Code Execution #Swiper
Daily CyberSecurity
CVE-2026-27212: Critical Swiper Prototype Pollution Flaw (CVSS 9.4) Exposes Global Apps
Critical prototype pollution flaw (CVE-2026-27212) in the Swiper npm package allows RCE, DoS, and auth bypass. Update to version 12.1.2 immediately.
⤷ Title: CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 12 Apr 2026 17:10:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS IMDSv2 #Axios #Cloud Security #CVE_2026_40175 #Header injection #infosec #javascript #Node.js #Prototype Pollution #rce #request smuggling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 12 Apr 2026 17:10:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS IMDSv2 #Axios #Cloud Security #CVE_2026_40175 #Header injection #infosec #javascript #Node.js #Prototype Pollution #rce #request smuggling
Daily CyberSecurity
CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
A critical CVSS 10 flaw in Axios (CVE-2026-40175) allows attackers to bypass AWS IMDSv2 and achieve RCE via header injection. Upgrade to v1.15.0 now!
⤷ Title: Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 12:01:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation #CVSS 10 #infosec #JavaScript Security #n8n #Node.js #Patch Alert #Prototype Pollution #rce #Webhook Security #XML parsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 12:01:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation #CVSS 10 #infosec #JavaScript Security #n8n #Node.js #Patch Alert #Prototype Pollution #rce #Webhook Security #XML parsing
Daily CyberSecurity
Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis
Critical CVSS 10 and 9.4 vulnerabilities hit n8n. Prototype pollution in XML nodes can lead to full RCE. Patch to v2.18.1 or v1.123.32 immediately.