building top-tier security tooling · breaking open source & filing the CVEs
found by manual source review, reported privately, published after the fix shipped.
| cve | target | class | severity |
|---|---|---|---|
| CVE-2026-50112 | Apache CloudStack | RCE + SSRF → root on KVM host | 🔴 Critical |
| CVE-2026-58123 | Hermes WebUI | unauthenticated RCE (terminal API) | 🔴 Critical · 9.3 |
| CVE-2026-53975 | OpenChamber | unauthenticated RCE (command injection) | 🔴 Critical · 9.3 |
| CVE-2026-53983 | Ground Station | blind SSRF (orbital data URL) | 🔴 Critical · 9.2 |
| CVE-2026-10142 | kafka-python | DoS (excessive memory allocation) | 🟠 High · 8.7 |
more disclosures
| cve | target | class | severity |
|---|---|---|---|
| CVE-2026-45229 | quark-auto-save | mass assignment → credential takeover | High |
| CVE-2026-47092 | claude-hud | arbitrary command execution via COMSPEC | High |
| CVE-2026-43982 | algernon | path-traversal file write via savein() |
High |
| CVE-2026-43981 | algernon | race condition → DoS via shared LState | High |
| CVE-2026-47091 | claude-hud | path traversal via transcript_path |
Medium |
| CVE-2026-45228 | quark-auto-save | stored XSS via system configuration | Medium |
| CVE-2026-47090 | claude-hud | terminal injection via OSC 8 hyperlinks | Low |
full writeups → github.com/KatrielMoses/cves
open source? i'll break it for free.
you get → full manual source review
→ private report with a working PoC
→ CVE filed + advisory published, after your fix ships
→ a note confirming the project was reviewed & patched
catch → it has to be open source
turnaround→ a weekend. two at most.



