Remote Code Execution in Ollama via Interactive Agent Allowlist Bypass
The Ollama interactive agent extracts a command prefix that ignores shell chaining operators, letting an allowed benign command smuggle arbitrary RCE.
Deep technical analysis, vulnerability write-ups, and offensive security research from the Faseel team — shared to help defenders stay ahead of real-world attacks.
The Ollama interactive agent extracts a command prefix that ignores shell chaining operators, letting an allowed benign command smuggle arbitrary RCE.
An authentication gateway reflected arbitrary Origins with credentials on its Pushed Authorization Request endpoint, allowing cross-origin theft of the OAuth request_uri and full ATO.
A support subdomain pointed at a decommissioned enterprise-SaaS tenant (NXDOMAIN), creating a high-trust phishing and credential-harvesting vector.
An SDK's remote-signing example logged the wallet master seed and API secrets in plaintext, shipped hardcoded passwords, and included a validator that approves every signing request.
A JS OAuth SDK hardcoded the state parameter to undefined, disabling CSRF protection, and logged authorization codes to the console with a fail-open auth fallback.
A default Dify deployment ships a hardcoded session-signing key and default Postgres password — chainable into full admin session forgery.
Next.js SSG pre-rendered per-user routes into public JSON, exposing internal user UUIDs and confirming privileged accounts to unauthenticated attackers.
Deep technical analysis, vulnerability write-ups, and offensive security research from the Faseel team — shared to help defenders stay ahead of real-world attacks.
The Ollama interactive agent extracts a command prefix that ignores shell chaining operators, letting an allowed benign command smuggle arbitrary RCE.
An authentication gateway reflected arbitrary Origins with credentials on its Pushed Authorization Request endpoint, allowing cross-origin theft of the OAuth request_uri and full ATO.
A support subdomain pointed at a decommissioned enterprise-SaaS tenant (NXDOMAIN), creating a high-trust phishing and credential-harvesting vector.
An SDK's remote-signing example logged the wallet master seed and API secrets in plaintext, shipped hardcoded passwords, and included a validator that approves every signing request.
A JS OAuth SDK hardcoded the state parameter to undefined, disabling CSRF protection, and logged authorization codes to the console with a fail-open auth fallback.
A default Dify deployment ships a hardcoded session-signing key and default Postgres password — chainable into full admin session forgery.
Next.js SSG pre-rendered per-user routes into public JSON, exposing internal user UUIDs and confirming privileged accounts to unauthenticated attackers.