Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Blog

Ostorlab Blog

Vulnerability research, CVE deep dives and engineering write-ups from the Ostorlab team on AI pentesting and mobile, web and API security testing.

Featured Stories See all articles →

A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain Community JavaScript package (< 1.1.14). The RecursiveUrlLoader class uses a naive string prefix check to validate crawled URLs, allowing an attacker to bypass the default preventOutside restriction with a suffixed domain and redirect the crawler to internal network assets, potentially exposing sensitive credentials and metadata endpoints.

Security

DORA Compliance for Mobile Teams: Understanding scope and what you need to do

A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define y...

Mar 03, 2026

Security

Top 10 Mobile App Penetration Testing Tools (2026)

The 10 tools our team uses to pentest mobile apps, from Frida, Ghidra and Jadx to mitmproxy and N...

Feb 27, 2026

Security

CVE-2025-64712: Path Traversal RCE in Unstructured Library MSG Processing

A technical breakdown of CVE-2025-64712, a CVSS 9.8 critical path traversal remote code execution...

Feb 23, 2026

Read by Topic

Latest from Engineering, Product & Security

False positives are an engineering-capacity problem, not only a scanner-quality problem. Learn how to measu...

Sep 28, 2026

Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan follows evid...

Jul 22, 2026

Learn how source code security testing works, why traditional SAST creates false positives, and how agentic...

Jul 16, 2026

Ostorlab fits teams testing connected mobile, web, API, and code assets on every release. Where it fits, wh...

Sep 28, 2026

How Ostorlab's Deep Agentic Scan uncovers and empirically proves complex vulnerabilities across web, mobile...

Sep 23, 2026

Compare Ostorlab, Invicti, Burp Suite DAST, HCL AppScan and Fortify for on-premises AppSec testing: deploym...

Sep 15, 2026

Ostorlab vs. pentesting firms: cost, testing frequency, depth and remediation, and when to use AI pentests,...

Sep 25, 2026

API-only scanners miss attack chains that start with secrets or routes in mobile apps, web bundles, or code...

Sep 25, 2026

Compare Ostorlab, XBOW, Aikido, Intruder, Escape and Penti for SOC 2 pentests on exploit evidence, human re...

Sep 25, 2026