Massagold
Stored XSS via unescaped EJS output, CSP bypassed using a Google JSONP endpoint, payload delivered to an admin bot that exfiltrated the flag from the admin inbox back to us.
Stored XSS via unescaped EJS output, CSP bypassed using a Google JSONP endpoint, payload delivered to an admin bot that exfiltrated the flag from the admin inbox back to us.
An Elysia backend's signed session cookie fails to verify signatures (CVE-2025-66457), letting a forged session=inside cookie bypass auth.