Home

Research

Advisories, 0days and research published by Fenrisk. The technical proof of our level of expertise.

Open Build Service, one year later: command execution through Mercurial argument injection
0day - Command execution - openSUSE OBS - CVE-2026-56004

Open Build Service, one year later: command execution through Mercurial argument injection

In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family. It has now been reported to the openSUSE security team and fixed…

Maxime Rinaudo · 6 min read
CVSS 10.0
HTTP Request Smuggling in Hiawatha - CVE-2026-51785
0day - HTTP Smuggling - Hiawatha - CVE-2026-51785

HTTP Request Smuggling in Hiawatha - CVE-2026-51785

As part of our ongoing research into request smuggling, we identified an HTTP Request Smuggling vulnerability (CWE-444) in Hiawatha ≤ 12.1. Hiawatha is an open-source, security-focused web server for Unix-like systems, used to serve websites and host web applications.

Lucas Coussement · 10 min read
CVSS 9.8
MCPwned: a Burp Suite extension for auditing MCP servers
Tooling - Scanner Exploitation

MCPwned: a Burp Suite extension for auditing MCP servers

This blog post quickly outlines the MCP protocol before presenting a Burp Suite extension developed by Fenrisk that enables pentesters to effectively test MCP servers.

Raphaël Lacroix · 6 min read
Remote code execution in CentOS Web Panel - CVE-2025-70951
0day - RCE - CentOS Web Panel - CVE-2025-70951

Remote code execution in CentOS Web Panel - CVE-2025-70951

As part of our ongoing research into web hosting control panels, we recently published an analysis of Control Web Panel (CWP), a widely used open-source administration panel designed to manage web servers running…

· 4 min read
CVSS 9.0
Detecting Jira & Confluence Versions and Mapping Known CVEs
Tooling - Scanner

Detecting Jira & Confluence Versions and Mapping Known CVEs

This blog post presents a tool that identifies the version of the Atlassian Jira or Confluence application and maps the identified version to a local CVE database. The detection is primarily based on the presence of…

Youssef Azefzaf · 3 min read
Remote code execution in aaPanel - CVE-2025-48702
0day - authenticated RCE - aaPanel - CVE-2025-48702

Remote code execution in aaPanel - CVE-2025-48702

aaPanel is a free and open-source web hosting control panel designed to simplify server management for Linux-based systems. It provides a graphical interface to manage web servers, websites,…

Maxime Rinaudo · 3 min read
CVSS 8.5
Remote code execution in CentOS Web Panel - CVE-2025-48703
0day - pre-auth RCE - CentOS Web Panel - CVE-2025-48703

Remote code execution in CentOS Web Panel - CVE-2025-48703

CentOS Web Panel (CWP) is a free web hosting control panel used to manage servers based on CentOS and other RPM-based distributions. CWP was first introduced in 2013 as a free, open-source web hosting control panel…

Maxime Rinaudo · 6 min read
CVSS 9.0
Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service
0day - File read/write - openSUSE OBS - CVE-2024-22033

Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service

Open Build Service (OBS) is an open-source distribution development platform provided by openSUSE. It allows developers to manage the whole packaging process in order to build a package from a simple software source and…

Maxime Rinaudo · 9 min read
CVSS 6.3
Supply Chain Attacks on Linux distributions - Fedora Pagure
0day - RCE - Fedora Pagure - CVE-2024-47516

Supply Chain Attacks on Linux distributions - Fedora Pagure

As discussed in the meta-article, we picked Pagure from the Fedora Apps Directory and already had a technical approach in mind. A software forge is likely to be a good target for an argument injection: we can expect the…

Thomas Chauchefoin · 9 min read
CVSS 9.8
Supply Chain Attacks on Linux distributions - Overview
Research - State of the Art

Supply Chain Attacks on Linux distributions - Overview

Supply chain attacks have been a trendy topic in the past years. Rather than directly attacking their primary target, attackers infiltrate less secure assets, such as software dependencies, firmware, or service…

Maxime Rinaudo · 6 min read
Gadget chains in Laravel
0day - PHP POP chain - Laravel

Gadget chains in Laravel

As we have seen in the previous article about wordpress gadgets, very simple gadget chains can be found in major projects. But sometimes finding popchain may be more difficult. This article…

Maxime Rinaudo · 3 min read
Gadget chains in Wordpress
0day - PHP POP chain - WordPress

Gadget chains in Wordpress

Exploiting an unserialization vulnerability in WordPress never was a small issue. Unlike other PHP frameworks, and until very recently, WordPress was not known for hosting gadget chains.

Maxime Rinaudo · 3 min read