Open Build Service, one year later: command execution through Mercurial argument injection
In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family. It has now been reported to the openSUSE security team and fixed…
Remote code execution in aaPanel - CVE-2025-48702
aaPanel is a free and open-source web hosting control panel designed to simplify server management for Linux-based systems. It provides a graphical interface to manage web servers, websites,…
Remote code execution in CentOS Web Panel - CVE-2025-48703
CentOS Web Panel (CWP) is a free web hosting control panel used to manage servers based on CentOS and other RPM-based distributions. CWP was first introduced in 2013 as a free, open-source web hosting control panel…
Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service
Open Build Service (OBS) is an open-source distribution development platform provided by openSUSE. It allows developers to manage the whole packaging process in order to build a package from a simple software source and…
Supply Chain Attacks on Linux distributions - Overview
Supply chain attacks have been a trendy topic in the past years. Rather than directly attacking their primary target, attackers infiltrate less secure assets, such as software dependencies, firmware, or service…
Gadget chains in Laravel
As we have seen in the previous article about wordpress gadgets, very simple gadget chains can be found in major projects. But sometimes finding popchain may be more difficult. This article…
Gadget chains in Wordpress
Exploiting an unserialization vulnerability in WordPress never was a small issue. Unlike other PHP frameworks, and until very recently, WordPress was not known for hosting gadget chains.
