Daily Writeups
3.48K subscribers
2 photos
127K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Prototype Pollution Masterclass: Practical Exploits, Detection & Node.js RCE
════════════════════════
𐀪 Author: PyUs3r
════════════════════════
Time: Mon, 06 Oct 2025 00:00:02 GMT
════════════════════════
Tags: #cybersecurity #bug_bounty #prototype_pollution #web_security #nodejs
Title: CyCTF25: I Hate Tasks Official Writeup
════════════════════════
𐀪 Author: Abdelnour Osman (DarkT)
════════════════════════
Time: Sat, 08 Nov 2025 21:15:19 GMT
════════════════════════
Tags: #web_exploitation #ctf_writeup #prototype_pollution #capture_the_flag #cybersecurity
Title: “RondoDoX” Strikes Back: Exposed Logs Reveal Massive 9-Month Campaign Targeting Next.js and IoT
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 31 Dec 2025 02:33:19 +0000
════════════════════════
Tags: #Malware #botnet #CloudSEK #CVE_2025_55182 #IoT security #Next.js #Prototype Pollution #rce #React2Shell #RondoDox #Server Actions #Web Framework Security #XMRig
Title: Prototype Pollution → Template Injection → RCE The Vulnerable Node Lab That Finally Made It Click
════════════════════════
𐀪 Author: ParadoxYab
════════════════════════
Time: Wed, 31 Dec 2025 09:03:44 GMT
════════════════════════
Tags: #rce #ssti #prototype_pollution #web_hacking #cybersecurity
Title: Menemukan Kerentanan Prototype Pollution di Absensi Pemerintahan: Lessons Learned dari Penetration…
════════════════════════
𐀪 Author: Ahmadfaizabdillah
════════════════════════
Time: Sun, 04 Jan 2026 11:27:49 GMT
════════════════════════
Tags: #hacking #cve #vulnerability #prototype_pollution #bug_hunting
Title: HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
Title: Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Wed, 11 Feb 2026 00:37:56 +0000
════════════════════════
Tags: #Vulnerability Report #Array Taint Bypass #CVE_2026_25881 #JavaScript Security #Patch Alert #Prototype Pollution #Remote Code Execution #Sandbox Escape #SandboxJS #Web Security
Title: CVE-2026-27212: Critical Swiper Prototype Pollution Flaw (CVSS 9.4) Exposes Global Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Tue, 24 Feb 2026 00:12:32 +0000
════════════════════════
Tags: #Vulnerability Report #AppSec #CVE_2026_27212 #Cyber Security #infosec #JavaScript Security #npm Vulnerability #Patch Alert #Prototype Pollution #Remote Code Execution #Swiper
Title: CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Sun, 12 Apr 2026 17:10:09 +0000
════════════════════════
Tags: #Vulnerability Report #AWS IMDSv2 #Axios #Cloud Security #CVE_2026_40175 #Header injection #infosec #javascript #Node.js #Prototype Pollution #rce #request smuggling
Title: Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 24 Apr 2026 12:01:16 +0000
════════════════════════
Tags: #Vulnerability Report #Automation #CVSS 10 #infosec #JavaScript Security #n8n #Node.js #Patch Alert #Prototype Pollution #rce #Webhook Security #XML parsing
Title: Gadget Hunting in Practice
════════════════════════
𐀪 Author: Marduk I Am
════════════════════════
Time: Sun, 17 May 2026 21:34:57 GMT
════════════════════════
Tags: #cybersecurity #xss_attack #prototype_pollution #web_security #bug_bounty
Title: Three Critical 9.4 CVSS Flaws Expose n8n Automation Nodes to Full RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Mon, 18 May 2026 01:20:46 +0000
════════════════════════
Tags: #Vulnerability Report #Argument Injection #CVE_2026_44789 #CVE_2026_44790 #CVE_2026_44791 #DevSecOps #infosec #n8n #Patch Alert #Prototype Pollution #rce #Workflow Automation
Title: Five Critical vm2 Vulnerabilities Grant Instant Node.js Host RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Fri, 22 May 2026 02:30:45 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_47137 #CVE_2026_47140 #CVE_2026_47210 #Cyber Security #infosec #JSPI Promise #Node.js Sandbox Escape #patch bypass #Prototype Hijacking #Remote Code Execution #vm2 sandbox
Title: React Router Vulnerabilities Patched in New Framework Releases
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 04 Jun 2026 02:40:36 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_42211 #Denial of Service #npm Package #Prototype Pollution #React Router #software update
Title: New Patches Eradicate Dangerous Axios Proxy Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 04 Jun 2026 01:30:45 +0000
════════════════════════
Tags: #Vulnerability Report #Axios #CVE_2026_44492 #CVE_2026_44494 #infosec #Node.js #Prototype Pollution #Proxy Bypass
Title: i18next Prototype Pollution Flaw (CVSS 9.1) Threatens 1M+ Weekly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 18 Jun 2026 01:00:39 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2026_48713 #CVE_2026_48714 #i18next #i18next_fs_backend #Node.js Security #npm Vulnerability #Prototype Pollution
Title: A Deep-Dive Into Hunting Prototype Pollution on Hashnode Live
════════════════════════
𐀪 Author: MD Mehedi Hasan
════════════════════════
Time: Fri, 19 Jun 2026 10:21:49 GMT
════════════════════════
Tags: #hashcode #nodejsecurity #javascript_security #prototype_pollution #penetration_testing
Title: Fools Mate, Revenge — TryHackMe Writeup
════════════════════════
𐀪 Author: ghosteye
════════════════════════
Time: Sun, 05 Jul 2026 15:06:54 GMT
════════════════════════
Tags: #cwe_1321 #api_security #tryhackme #penetration_testing #prototype_pollution
Title: [Fools Mate, Revenge] — Prototype Pollution in a Express.js Chess App
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
Time: Wed, 15 Jul 2026 06:28:53 GMT
════════════════════════
Tags: #express_vulnerability #prototype_pollution #tryhackme_walkthrough #tryhackme
Title: Fool’s Mate (TryHackMe): I Checkmated the Bot, the Server Still Said No — So I Polluted Its…
════════════════════════
𐀪 Author: Syedmohathashimali
════════════════════════
Time: Sat, 18 Jul 2026 03:58:05 GMT
════════════════════════
Tags: #prototype_pollution #tryhackme #ctf #cybersecurity #web_security