<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Adel Assakaf - security research &amp; advisories</title>
    <link>https://assakaf.com/</link>
    <description>Original vulnerability research: advisories, CVEs and open-source security write-ups.</description>
    <language>en</language>
    <atom:link href="https://assakaf.com/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>[CVE-2026-59206] Prototype Pollution to Unauthenticated User Enumeration in n8n</title>
      <link>https://assakaf.com/articles/n8n-prototype-pollution-auth-bypass/</link>
      <guid isPermaLink="true">https://assakaf.com/articles/n8n-prototype-pollution-auth-bypass/</guid>
      <description>A two-level dynamic write in replaceInvalidCredentials pollutes Object.prototype from a default Member account, so req.user resolves for unauthenticated requests and every account email, role and MFA status leaks.</description>
      <pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Privilege Escalation to Superuser in Paperless-ngx</title>
      <link>https://assakaf.com/articles/paperless-ngx-privesc/</link>
      <guid isPermaLink="true">https://assakaf.com/articles/paperless-ngx-privesc/</guid>
      <description>A type-coercion slip in UserViewSet let any account holding auth.add_user create a full superuser. Published as GHSA-59xh-5vwx-4c4q, CVSS 7.1.</description>
      <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Contribution to ProjectDiscovery's httpx</title>
      <link>https://assakaf.com/articles/httpx-graceful-shutdown/</link>
      <guid isPermaLink="true">https://assakaf.com/articles/httpx-graceful-shutdown/</guid>
      <description>On interrupt, httpx saved a resume index based on dispatched targets, not completed ones, silently skipping 51 of 108 hosts on resume. PR #2393 makes shutdown drain in-flight work first.</description>
    </item>
    <item>
      <title>Contribution to Turbot's Steampipe (Google Workspace)</title>
      <link>https://assakaf.com/articles/steampipe-googleworkspace-reports/</link>
      <guid isPermaLink="true">https://assakaf.com/articles/steampipe-googleworkspace-reports/</guid>
      <description>Added an Admin Reports table to the Steampipe Google Workspace plugin: query Workspace audit logs (logins, admin actions, OAuth tokens, Drive, mobile) as SQL for detection and compliance. PR #88, merged.</description>
    </item>
  </channel>
</rss>
