⤷ Title: Vitest Flaw Rated CVSS 9.4 Hits an npm Package With 65 Million Weekly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 02:12:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #GHSA_p63j_vcc4_9vmv #javascript #npm #Path Traversal #Supply Chain Security #Vite #Vitest #Vitest Browser Mode
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 02:12:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #GHSA_p63j_vcc4_9vmv #javascript #npm #Path Traversal #Supply Chain Security #Vite #Vitest #Vitest Browser Mode
Daily CyberSecurity
Vitest Flaw Rated CVSS 9.4 Hits an npm Package With 65 Million Weekly Downloads
TL;DR Vitest patched a critical vulnerability rated CVSS 9.4. Browser Mode commands could read, write, or delete files outside the project folder. They did so even when the allowWrite gate was set…
⤷ Title: TryHackMe: Room 404 Walkthrough | Hacker Holidays — Day 2
════════════════════════
𐀪 Author: Rishi Kumavat
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 04:13:25 GMT
════════════════════════
⌗ Tags: #python #tryhackme #javascript #programming #tech
════════════════════════
𐀪 Author: Rishi Kumavat
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 04:13:25 GMT
════════════════════════
⌗ Tags: #python #tryhackme #javascript #programming #tech
Medium
TryHackMe: Room 404 Walkthrough | Hacker Holidays — Day 2
Welcome back to another writeup! Today, we’re checking into The Byte Lotus Hotel for Day 2 of TryHackMe’s Hacker Holidays event.
⤷ Title: Verifiable Bookmarklets
════════════════════════
𐀪 Author: Roberto Vázquez González
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 09:57:34 GMT
════════════════════════
⌗ Tags: #javascript_development #bookmarklet #javascript #hacking #javascript_tips
════════════════════════
𐀪 Author: Roberto Vázquez González
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 09:57:34 GMT
════════════════════════
⌗ Tags: #javascript_development #bookmarklet #javascript #hacking #javascript_tips
Medium
Verifiable Bookmarklets
I just added a small new tool to the site: Verifiable Bookmarklets. Every bookmarklet it generates carries a SHA-256 fingerprint, so anyone…
⤷ Title: Learning CORS the Right Way: Understanding the Browser Before the Attack
════════════════════════
𐀪 Author: Anandhu Kannan
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 18:12:31 GMT
════════════════════════
⌗ Tags: #portswigger #ethical_hacking #javascript #bug_bounty #cors
════════════════════════
𐀪 Author: Anandhu Kannan
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 18:12:31 GMT
════════════════════════
⌗ Tags: #portswigger #ethical_hacking #javascript #bug_bounty #cors
Medium
Learning CORS the Right Way: Understanding the Browser Before the Attack
Understanding CORS from Scratch (Developer’s Perspective)
⤷ Title: Shai-Hulud npm Worm Compromises Supply Chain
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 14:20:36 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #JavaScript #malware #npm #Shai_Hulud #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 14:20:36 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #JavaScript #malware #npm #Shai_Hulud #supply chain attack
Information Security News
Shai-Hulud npm Worm Compromises Supply Chain
The Initial JavaScript Breach A single installation of a routine JavaScript library could expose a company’s cloud infrastructure, repositories, and internal services to attackers. The Shai-…
⤷ Title: The Premium Feature That Was Only One API Request Away
════════════════════════
𐀪 Author: L0Ay
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 17:37:36 GMT
════════════════════════
⌗ Tags: #javascript #penetration_testing #bug_bounty_writeup #bug_bounty #bug_bounty_tips
════════════════════════
𐀪 Author: L0Ay
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 17:37:36 GMT
════════════════════════
⌗ Tags: #javascript #penetration_testing #bug_bounty_writeup #bug_bounty #bug_bounty_tips
Medium
The Premium Feature That Was Only One API Request Away
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ
⤷ Title: WebGPU: Hacking 101
════════════════════════
𐀪 Author: Pratik Sharma
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 20:49:13 GMT
════════════════════════
⌗ Tags: #javascript #programming #security #hacking
════════════════════════
𐀪 Author: Pratik Sharma
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 20:49:13 GMT
════════════════════════
⌗ Tags: #javascript #programming #security #hacking
Medium
WebGPU: Hacking 101
WebGPU Gives Websites Access to Your GPU. So Why Can’t a Page Read Your VRAM?
⤷ Title: DOM XSS using web messages
════════════════════════
𐀪 Author: Mubin mujawar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_vulnerability #portswigger #javascript #web_security
════════════════════════
𐀪 Author: Mubin mujawar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_vulnerability #portswigger #javascript #web_security
Medium
DOM XSS using web messages
Exploiting an Unchecked postMessage Listener — DOM XSS Using Web Messages (PortSwigger Academy)
⤷ Title: How a JavaScript file led me to an Admin Access
════════════════════════
𐀪 Author: Said-Abbosxon Nabijonov | 0trc
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 09:05:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #infosec #pentesting #javascript
════════════════════════
𐀪 Author: Said-Abbosxon Nabijonov | 0trc
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 09:05:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #infosec #pentesting #javascript
Medium
How a JavaScript file led to an Admin Access
During a pentest I found a JavaScript file that led to me an API with exposed Swagger. Once account creation later I was an Admin.
Forwarded from Bug Bounty Diary
✎ Extract & Download All JavaScript Files for Recon
For modern web apps, scraping
My Approach:
1. Open DevTools → Network
2. Enable Preserve log
3. Crawl the target and visit relevant pages/features
4. Interact with the application to trigger dynamic resources
5. Export the traffic as a HAR
6. Extract all JavaScript files from
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
For modern web apps, scraping
<script> tags or relying on Burp's Site Map often isn't enough. Why? Because applications may dynamically load JavaScript from CDNs, cross-origin domains, specific routes (Lazy Loading), or after user interactions.My Approach:
1. Open DevTools → Network
2. Enable Preserve log
3. Crawl the target and visit relevant pages/features
4. Interact with the application to trigger dynamic resources
5. Export the traffic as a HAR
6. Extract all JavaScript files from
.HAR file using unhar (I'll talk about it in the next post.)#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
❤1
Forwarded from Bug Bounty Diary
✎ Unhar - Extract, Unminify, Beautify Javascript files from .Har file
In the previous post, I explained my approach to capturing and downloading a website’s JavaScript resources into a
unhar turns a raw
In short: HAR → Extract → Source Maps → Beautify → Ready for Analysis
● Installation
● Usage
• Repository: Github
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
In the previous post, I explained my approach to capturing and downloading a website’s JavaScript resources into a
.HAR file for further local analysis. Now, let’s take it a step further with unhar and process that HAR files. unhar turns a raw
.HAR file into a structured set of web assets for local analysis. It extracts unique JavaScript and HTML resources while preserving the original URL structure, fetches available source maps, beautifies/unminifies JavaScript, and extracts inline scripts from HTML pages.In short: HAR → Extract → Source Maps → Beautify → Ready for Analysis
● Installation
git clone https://github.com/Spix0r/unhar
cd unhar
● Usage
# custom output directory
python3 unhar.py site.har --output folder
# skip source map fetching
python3 unhar.py site.har --no-srcmap
# skip beautify
python3 unhar.py site.har --no-beautify
• Repository: Github
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
⤷ Title: JAVA SCRIPT DEOBFUSCATION
════════════════════════
𐀪 Author: Hassan Saif
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 16:33:55 GMT
════════════════════════
⌗ Tags: #js_deobfuscation_walk_thr #hackthebox_writeup #js_deobfuscation #javascript #hackthebox
════════════════════════
𐀪 Author: Hassan Saif
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 16:33:55 GMT
════════════════════════
⌗ Tags: #js_deobfuscation_walk_thr #hackthebox_writeup #js_deobfuscation #javascript #hackthebox
Medium
MODULE 06 — JAVA SCRIPT DEOBFUSCATION
MODULE 06 — JAVA SCRIPT DEOBFUSCATION To access the lab visit the following link: https://academy.hackthebox.com/app/module/41 Obfuscation …
⤷ Title: Systematic JavaScript Reconnaissance
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 14:54:34 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #infosec #reconnaissance #cybersecurity
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 14:54:34 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #infosec #reconnaissance #cybersecurity
Medium
Systematic JavaScript Reconnaissance
JavaScript surely knows too much.
⤷ Title: JavaScript: Simple Demo — Try Hack Me
════════════════════════
𐀪 Author: Chittanoori Divyashrith
════════════════════════
ⴵ Time: Fri, 04 Sep 2026 07:13:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #javascript_simple_demo #pre_security #tryhackme
════════════════════════
𐀪 Author: Chittanoori Divyashrith
════════════════════════
ⴵ Time: Fri, 04 Sep 2026 07:13:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #javascript_simple_demo #pre_security #tryhackme
Medium
JavaScript: Simple Demo — Try Hack Me
Task 1 — Introduction
⤷ Title: Finding Secrets Inside JavaScript Files
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Sat, 05 Sep 2026 22:53:39 GMT
════════════════════════
⌗ Tags: #javascript #cybersecurity #ethical_hacking #bug_bounty #technology
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Sat, 05 Sep 2026 22:53:39 GMT
════════════════════════
⌗ Tags: #javascript #cybersecurity #ethical_hacking #bug_bounty #technology
Medium
Finding Secrets Inside JavaScript Files
Learn how I analyze JavaScript files during reconnaissance to uncover API endpoints, secrets, and other valuable information for bug bounty…
⤷ Title: Cloudflare Raises Workers Size Limit to 64 MiB for Free and Paid Plans
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 03:46:37 +0000
════════════════════════
⌗ Tags: #Technology #cloudflare #Cloudflare Workers #developer platform #Edge Computing #JavaScript bundle #serverless #Workers size limit #Wrangler
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 03:46:37 +0000
════════════════════════
⌗ Tags: #Technology #cloudflare #Cloudflare Workers #developer platform #Edge Computing #JavaScript bundle #serverless #Workers size limit #Wrangler
Daily CyberSecurity
Cloudflare Raises Workers Size Limit to 64 MiB for Free and Paid Plans
According to the changelog published by Cloudflare, from today both the free and paid Workers subscription plans support uncompressed code bundles of up to 64 MiB. Previously, Workers judged wheth…
⤷ Title: Common Sensitive Files You Should Look For During Web Recon
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 19:17:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #javascript #technology #hacking
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 19:17:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #javascript #technology #hacking
Medium
Common Sensitive Files You Should Look For During Web Recon
A beginner-friendly guide to finding publicly accessible files that can reveal valuable information during bug bounty reconnaissance.
⤷ Title: A Browser-Visible API Key Is Evidence, Not a Verdict
════════════════════════
𐀪 Author: Lars at Veristria
════════════════════════
ⴵ Time: Tue, 08 Sep 2026 10:32:33 GMT
════════════════════════
⌗ Tags: #javascript #incident_response #cybersecurity #api_security #devsecops
════════════════════════
𐀪 Author: Lars at Veristria
════════════════════════
ⴵ Time: Tue, 08 Sep 2026 10:32:33 GMT
════════════════════════
⌗ Tags: #javascript #incident_response #cybersecurity #api_security #devsecops
Medium
A Browser-Visible API Key Is Evidence, Not a Verdict
How to separate intended public identifiers from real client-side secret exposure
⤷ Title: When JavaScript Gets Confused: A Look at Chrome’s V8 Vulnerabilities
════════════════════════
𐀪 Author: Fatima Zakir
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 22:04:20 GMT
════════════════════════
⌗ Tags: #javascript #vulnerability #technology #hacking #cybersecurity
════════════════════════
𐀪 Author: Fatima Zakir
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 22:04:20 GMT
════════════════════════
⌗ Tags: #javascript #vulnerability #technology #hacking #cybersecurity
Medium
When JavaScript Gets Confused: A Look at Chrome’s V8 Vulnerabilities
Let’s talk about CVE-2026–85046
⤷ Title: vm2’s Sandbox Just Failed for the Third Time This Week.
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
Medium
vm2’s Sandbox Just Failed for the Third Time This Week. A Million Weekly Downloads Are Still Running It
Three separate CVSS 10.0 sandbox escapes landed days apart — in a library that was declared dead once already