whoareme.com
HomeBlogAbout
# The blog

All posts

Everything I’ve written, sorted newest first.

Aug 25, 2026

Plausible Analytics: Pre-Auth RCE, Cross-Tenant IDORs, and SSRF-to-RCE

Multiple critical vulnerabilities at Plausible Analytics: pre-auth Storybook RCE, registration bypass with cross-tenant IDORs and stored XSS, and SSO verification SSRF to PostgreSQL RCE.

Security
Apr 16, 2026

$15k - CSPT to full account takeover, then 2FA bypass via the prototype chain

A client-side path traversal in the front-end's URL builder turned into arbitrary PUT/DELETE on the API, then chained with an inherited-property lookup bug to bypass 2FA

Security
Mar 9, 2020

SSRF in Ghost CMS via oEmbed (CVE-2020-8134)

How Ghost's embed-anything input let an authenticated publisher pivot the server into cloud metadata endpoints - and what the fix actually changed.

Security
Logo© 2026 whoareme - security research
RSSAbout