[ BLOGS ]

Where Dev Teams Learn Faster

Where Dev Teams Learn Faster

Where Dev Teams Learn Faster

1000+ engineering teams have made CodeAnt AI the last line of defence before every deployment

Trusted by Startups to Fortune 100

Featured

AI PENTESTING

Claude Code Sandbox
Escape on macOS

Sonali Sood

Founding GTM, CodeAnt AI

The Log4j2 Filter That Only Does Half Its Job

Code Security

Dissecting FOIS: The Log4j2 Filter That Only Does Half Its Job

Log4j2's FilteredObjectInputStream checks which classes can be rebuilt, but not how large or deep the data can be. Here's how that gap enables an RCE and two gadget-free crashes on a serialized log receiver.

Claude Code Action Bug: Security Flaw Lets Triage Roles Inject Data

Code Security

Claude Code Action Bug: Security Flaw Lets Triage Roles Inject Data

A triage-role GitHub collaborator could move a Claude Code Action run's authorized trigger boundary and inject post-authorization input into a repo-writing job.

Claude Code Security Flaw: Sandboxed Code Overwrites Host Files

Code Security

Claude Code Security Flaw: Sandboxed Code Overwrites Host Files

A filesystem identity race allowed code confined to Claude Code's macOS Bash sandbox to redirect the host-owned Edit tool and overwrite user-writable files outside the workspace.

CVE-2026-71511: Redaction Bug Exposes Password Hashes

AI Pentesting

CVE-2026-71511: Redaction Bug Exposes Password Hashes

A redaction bug (CVE-2026-71511, CVSS 6.5) left Dolibarr's members API exposing every member's password hash to any account that could read member records.

CVE-2026-71510: Blind Search Leaks Dolibarr Salaries

AI Pentesting

CVE-2026-71510: Blind Search Leaks Dolibarr Salaries Copy

A blind authorization flaw (CVE-2026-71510, CVSS 6.5) let attackers infer hidden Dolibarr salaries and password hashes through yes/no search queries.

CVE-2026-71509: Employees Can Approve Their Own Expenses6-71508: Mass Assignment Bug Rewrites Salary

AI Pentesting

CVE-2026-71509: Employees Can Approve Their Own Expenses

An access-control bug (CVE-2026-71509, CVSS 6.5) let Dolibarr employees approve their own expense claims and their team's, bypassing separation of duties.

CVE-2026-71508: Mass Assignment Bug Rewrites Salary

AI Pentesting

CVE-2026-71508: Mass Assignment Bug Rewrites Salary

A mass assignment bug (CVE-2026-71508, CVSS 6.5) let Dolibarr employees rewrite their own salary through a profile update, hidden from the API response.

CVE-2026-71507: BOLA Bug Redirects Supplier Payments

AI Pentesting

CVE-2026-71507: BOLA Bug Redirects Supplier Payments

A BOLA bug (CVE-2026-71507, CVSS 6.5) let low-privilege Dolibarr accounts rewrite supplier bank details and redirect real payment batches.

CVE-2026-71506: Wrong-Permission Bug Deletes Payments

AI Pentesting

CVE-2026-71506: Wrong-Permission Bug Deletes Payments

A wrong-permission bug (CVE-2026-71506, CVSS 6.5) let low-privilege Dolibarr accounts delete real payments, turning paid invoices back into phantom debt.

BOLA Bug Exposes Dolibarr Invoices

AI Pentesting

CVE-2026-71505: BOLA Bug Exposes Dolibarr Invoices

A BOLA bug (CVE-2026-71505, CVSS 8.1) let low-privilege Dolibarr accounts reset any company's portal password and read their private invoices.

CVE-2026-71504: Mass Assignment Bug Resets Admin Password

AI Pentesting

CVE-2026-71504: Mass Assignment Bug Resets Admin Password

A mass assignment bug (CVE-2026-71504, CVSS 8.3) let a low-privilege Dolibarr account reset the admin's password. See the exploit chain and the fix.

CVE-2026-71503: How a Single Reflected XSS Bug Mints a Rogue Admin in Dolibarr

AI Pentesting

CVE-2026-71503: How a Single Reflected XSS Bug Mints a Rogue Admin in Dolibarr

A reflected XSS bug in Dolibarr (CVE-2026-71503, CVSS 9.3) lets attackers mint a hidden admin account from one link. See how it works and how to fix it.

Let AI Fix Your Code, You Build the Future

Get Pentest Report

NO CC REQUIRED