Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Author

Aziz Elbelaychy

Security Engineer

Aziz is a Security Engineer Intern at Ostorlab. He specializes in application security and offensive security testing. He conducts deep-dive vulnerability analysis across web and mobile applications, leveraging his background in penetration testing, and also delivers vulnerability research and robust assessments to help organizations proactively secure their attack surfaces. His research and technical findings are rigorously reviewed by the Ostorlab engineering team for accuracy and reproducibility.

10 articles LinkedIn

See how Ostorlab's Agentic Deep Scan chained a Medium-severity OpenAPI disclosure and an SSRF vulnerability to bypass a loopback restriction and extract database credentials.

Security

Can SOC 2 Accept an AI-Conducted Penetration Test?

SOC 2 doesn't name a required testing method, so auditors judge evidence, not tools. Here's what ...

Aug 06, 2026

Security

How AI Catches Complex Vulnerabilities: Inside Agentic Pentesting and Exploit Chaining

Discover how agentic AI catches business logic flaws rule-based scanners miss. See a real exploit...

Jul 28, 2026

Security

DirtyFrag: Universal Linux Local Privilege Escalation via Page-Cache Write

A technical breakdown of DirtyFrag, a pair of Linux kernel local privilege escalation vulnerabili...

May 13, 2026

More by Aziz Elbelaychy

BeatBanker/BTMOB Android Banking Malware Analysis

Static analysis of TV_V_23.apk, BeatBanker/BTMOB Android banking malware disguised as a flashlight app: four-stage chain, anti-analysis, attribution and IOCs.

Apr 28, 2026

Roundcube IMAP Command Injection and SSRF Flaws

A deep dive into two critical vulnerabilities uncovered in Roundcube Webmail (< 1.6.14, 1.5.14, 1.7 RC4) during a source code review. OVE-2026-8 allows authenticated attackers to inject arbitrary IMAP commands via the _filter parameter due to missing CRLF sanitization. OVE-2026-9 enables Server-Side Request Forgery (SSRF) by exploiting the CSS proxying mechanism, allowing access to internal network resources and cloud metadata.

Apr 08, 2026

CVE-2026-27971 : Qwik server$ Unauthenticated Remote Code Execution

A technical breakdown of CVE-2026-27971, a CVSS 9.2 critical unauthenticated remote code execution vulnerability in Qwik (< 1.19.1). Unsafe deserialization in the server$ RPC flow allows attacker-controlled QRL objects to be reconstructed from application/qwik-json requests, enabling arbitrary module path and symbol resolution and, where require() is available,remote code execution via crafted server-side function invocation.

Apr 01, 2026

CVE-2025-68461: Roundcube SVG Animate XSS Bypass

CVE-2025-68461 (CVSS 7.2) lets SVG animate tags slip past the Roundcube sanitizer via namespace prefixes. PoC, patch analysis, Nuclei detection and mitigation.

Mar 17, 2026

CVE-2026-26019 : LangChain RecursiveUrlLoader Server-Side Request Forgery Vulnerability

A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain Community JavaScript package (< 1.1.14). The RecursiveUrlLoader class uses a naive string prefix check to validate crawled URLs, allowing an attacker to bypass the default preventOutside restriction with a suffixed domain and redirect the crawler to internal network assets, potentially exposing sensitive credentials and metadata endpoints.

Mar 04, 2026

CVE-2025-64712: Path Traversal RCE in Unstructured Library MSG Processing

A technical breakdown of CVE-2025-64712, a CVSS 9.8 critical path traversal remote code execution vulnerability in the Unstructured Python library (< 0.18.18). Unsanitized attachment filenames in Outlook MSG processing allow for path traversal, enabling an attacker to overwrite arbitrary files via a crafted MSG file and achieve code execution.

Feb 23, 2026