Accueil
author

Maxime Rinaudo

Maxime Rinaudo est le co-fondateur de Fenrisk ainsi que l'un de ses experts en sécurité. Il est également passionné par la sécurité des applications web. Après avoir travaillé dix années au sein du Ministère des armées et 3 ans en tant que consultant à Paris, Maxime à décidé de rejoindre Julien dans son aventure afin de partager leur vision de la sécurité offensive.

Open Build Service, one year later: command execution through Mercurial argument injection
0day - Command execution - openSUSE OBS - CVE-2026-56004

Open Build Service, one year later: command execution through Mercurial argument injection

In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family. It has now been reported to the openSUSE security team and fixed…

Maxime Rinaudo · 6 min de lecture
CVSS 10.0
Remote code execution in aaPanel - CVE-2025-48702
0day - authenticated RCE - aaPanel - CVE-2025-48702

Remote code execution in aaPanel - CVE-2025-48702

aaPanel is a free and open-source web hosting control panel designed to simplify server management for Linux-based systems. It provides a graphical interface to manage web servers, websites,…

Maxime Rinaudo · 3 min de lecture
CVSS 8.5
Remote code execution in CentOS Web Panel - CVE-2025-48703
0day - pre-auth RCE - CentOS Web Panel - CVE-2025-48703

Remote code execution in CentOS Web Panel - CVE-2025-48703

CentOS Web Panel (CWP) is a free web hosting control panel used to manage servers based on CentOS and other RPM-based distributions. CWP was first introduced in 2013 as a free, open-source web hosting control panel…

Maxime Rinaudo · 6 min de lecture
CVSS 9.0
Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service
0day - File read/write - openSUSE OBS - CVE-2024-22033

Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service

Open Build Service (OBS) is an open-source distribution development platform provided by openSUSE. It allows developers to manage the whole packaging process in order to build a package from a simple software source and…

Maxime Rinaudo · 9 min de lecture
CVSS 6.3
Supply Chain Attacks on Linux distributions - Overview
Research - State of the Art

Supply Chain Attacks on Linux distributions - Overview

Supply chain attacks have been a trendy topic in the past years. Rather than directly attacking their primary target, attackers infiltrate less secure assets, such as software dependencies, firmware, or service…

Maxime Rinaudo · 6 min de lecture
Gadget chains in Laravel
0day - PHP POP chain - Laravel

Gadget chains in Laravel

As we have seen in the previous article about wordpress gadgets, very simple gadget chains can be found in major projects. But sometimes finding popchain may be more difficult. This article…

Maxime Rinaudo · 3 min de lecture
Gadget chains in Wordpress
0day - PHP POP chain - WordPress

Gadget chains in Wordpress

Exploiting an unserialization vulnerability in WordPress never was a small issue. Unlike other PHP frameworks, and until very recently, WordPress was not known for hosting gadget chains.

Maxime Rinaudo · 3 min de lecture