Author
Aziz Elbelaychy
Aziz is a Security Engineer Intern at Ostorlab. He specializes in application security and offensive security testing. He conducts deep-dive vulnerability analysis across web and mobile applications, leveraging his background in penetration testing, and also delivers vulnerability research and robust assessments to help organizations proactively secure their attack surfaces. His research and technical findings are rigorously reviewed by the Ostorlab engineering team for accuracy and reproducibility.
The Map and the Window: How an Agentic Scan Chained a Documentation Leak Into Stolen Credentials
See how Ostorlab's Agentic Deep Scan chained a Medium-severity OpenAPI disclosure and an SSRF vulnerability to bypass a loopback restriction and extract database credentials.
Sep 23, 2026
Can SOC 2 Accept an AI-Conducted Penetration Test?
SOC 2 doesn't name a required testing method, so auditors judge evidence, not tools. Here's what ...
Aug 06, 2026
How AI Catches Complex Vulnerabilities: Inside Agentic Pentesting and Exploit Chaining
Discover how agentic AI catches business logic flaws rule-based scanners miss. See a real exploit...
Jul 28, 2026
DirtyFrag: Universal Linux Local Privilege Escalation via Page-Cache Write
A technical breakdown of DirtyFrag, a pair of Linux kernel local privilege escalation vulnerabili...
May 13, 2026
More by Aziz Elbelaychy
BeatBanker/BTMOB Android Banking Malware Analysis
Static analysis of TV_V_23.apk, BeatBanker/BTMOB Android banking malware disguised as a flashlight app: four-stage chain, anti-analysis, attribution and IOCs.
Apr 28, 2026
Roundcube IMAP Command Injection and SSRF Flaws
A deep dive into two critical vulnerabilities uncovered in Roundcube Webmail (< 1.6.14, 1.5.14, 1.7 RC4) during a source code review. OVE-2026-8 allows authenticated attackers to inject arbitrary IMAP commands via the _filter parameter due to missing CRLF sanitization. OVE-2026-9 enables Server-Side Request Forgery (SSRF) by exploiting the CSS proxying mechanism, allowing access to internal network resources and cloud metadata.
Apr 08, 2026
CVE-2026-27971 : Qwik server$ Unauthenticated Remote Code Execution
A technical breakdown of CVE-2026-27971, a CVSS 9.2 critical unauthenticated remote code execution vulnerability in Qwik (< 1.19.1). Unsafe deserialization in the server$ RPC flow allows attacker-controlled QRL objects to be reconstructed from application/qwik-json requests, enabling arbitrary module path and symbol resolution and, where require() is available,remote code execution via crafted server-side function invocation.
Apr 01, 2026
CVE-2025-68461: Roundcube SVG Animate XSS Bypass
CVE-2025-68461 (CVSS 7.2) lets SVG animate tags slip past the Roundcube sanitizer via namespace prefixes. PoC, patch analysis, Nuclei detection and mitigation.
Mar 17, 2026
CVE-2026-26019 : LangChain RecursiveUrlLoader Server-Side Request Forgery Vulnerability
A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain Community JavaScript package (< 1.1.14). The RecursiveUrlLoader class uses a naive string prefix check to validate crawled URLs, allowing an attacker to bypass the default preventOutside restriction with a suffixed domain and redirect the crawler to internal network assets, potentially exposing sensitive credentials and metadata endpoints.
Mar 04, 2026
CVE-2025-64712: Path Traversal RCE in Unstructured Library MSG Processing
A technical breakdown of CVE-2025-64712, a CVSS 9.8 critical path traversal remote code execution vulnerability in the Unstructured Python library (< 0.18.18). Unsanitized attachment filenames in Outlook MSG processing allow for path traversal, enabling an attacker to overwrite arbitrary files via a crafted MSG file and achieve code execution.
Feb 23, 2026