Skip to content

Latest commit

 

History

40 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

CVE and GHSA security research by Charles Vosburgh / the-vibe-dev

CVE & GHSA Security Research

31 distinct public vulnerability cases 23 public CVEs 14 published repository GitHub Security Advisories Researcher the-vibe-dev

Security vulnerability research by Charles Vosburgh / the-vibe-dev.

This repository is the authoritative public portfolio for Charles's CVE and repository-level GitHub Security Advisory work. Accepted Linux kernel security fixes are documented separately in the-vibe-dev/Linux-Kernel.

Current portfolio snapshot

Metric Verified public count
Distinct public vulnerability cases 31
Public CVEs 23
Published repository GHSAs 14
Cases carrying both CVE and GHSA identifiers 6

Counting methodology

One vulnerability is represented by one canonical directory. When the same case has both a CVE and a repository GHSA, both identifiers appear in that directory rather than being counted as separate vulnerabilities.

The six overlap cases are TypeBox, isomorphic-git, both public vm2 cases, fast-xml-parser, and libheif. Accordingly, 23 CVEs + 14 GHSAs does not equal 37 vulnerabilities. The correct total is 31 distinct public cases: 14 repository-GHSA cases plus 17 other public CVE cases.

Global GitHub Advisory Database mirrors created from CVE records are useful references, but they are not counted as researcher-contributed repository advisories.

Vulnerability index

# Identifier(s) Project Public finding Public severity Write-up state Write-up
01 CVE-2026-73343 WP Compress Unauthenticated remote code execution Critical, 10.0 Summary-only Read
02 CVE-2026-15054 Bit Form Inactive or unpublished forms remained reachable through public submission handlers Low, 3.7 Full Read
03 CVE-2026-16534 Import and export users and customers CSV import authorization failure High, 7.2 Full Read
04 CVE-2026-64606 Apache Fory Java lambda class-registration bypass Important (Apache) / Critical, 9.8 (CISA ADP) Full Read
05 CVE-2026-75796 AI Engine Multisite account-target authorization failure High, 7.2 Full Read
06 CVE-2026-77789 Stripe Payment Forms by WP Full Pay Cross-customer subscription modification Medium, 4.3 Full Read
07 CVE-2026-77356 · GHSA-976x-prgx-qv35 TypeBox Generated validation-code injection High, 7.8 Full Read
08 CVE-2026-77355 · GHSA-6fxm-h49m-4fg3 isomorphic-git NTFS alias bypass writing into the active gitdir High, 8.8 Full Read
09 CVE-2026-47698 · GHSA-cfcw-xp6x-25gj vm2 Sandbox breakout through dangerous host prototype mutators Critical, 9.8 Full Read
10 CVE-2026-73569 · GHSA-8r6m-32jq-jx6q fast-xml-parser Repeated DOCTYPE declarations reset entity-expansion limits High, 8.7 Full Read
11 GHSA-5jx8-p6q2-455g DynamicExpresso LateBindObject reflection-restriction bypass High, 8.8 Full Read
12 GHSA-hphq-wq62-4mj3 OpenEXR HTJ2K planar decode row-endpoint wrap causing denial of service Moderate, 5.5 Full Read
13 GHSA-v3qq-3xvg-m77g python-statemachine Restricted-evaluator write-side dunder traversal Critical, 9.1 Full Read
14 GHSA-fj3w-533r-fvf6 python-statemachine Untrusted SCXML external-source local-file disclosure High, 7.1 Full Read
15 GHSA-g3jj-5cmm-3hxx fast-jwt Raw public JWK JSON accepted as an HMAC secret High, 7.4 Full Read
16 CVE-2026-92948 · GHSA-qhwx-74w5-xhxq vm2 NodeVM builtin allowlist bypass through node:test.run() Critical, 9.9 Full Read
17 CVE-2026-81766 Really Simple Security Multisite subsite Administrator plugin installation Medium, 6.6 Full Read
18 CVE-2026-17563 WP User Frontend Unauthenticated post creation through a subscription-gated form Not displayed by WPScan Full Read
19 CVE-2026-77793 RegistrationMagic Paid-registration bypass through an omitted price field Not displayed by WPScan Full Read
20 GHSA-9v3x-mhg4-wwv2 Exiv2 Out-of-bounds stack access in built-in HTTP request construction Low Full Read
21 CVE-2026-84451 · GHSA-hh47-fhqr-cj2r libheif Incomplete range-check fix allowed integer wrap and out-of-bounds read Moderate, 6.5 Full Read
22 CVE-2026-86815 BackWPup Missing authorization on a backup-management operation Medium, 5.5 Summary-only Read
23 CVE-2026-88764 Simple Membership Improper privilege management Medium, 5.4 Summary-only Read
24 CVE-2026-89080 Really Simple Security Email two-factor authentication bypass High, 7.5 Summary-only Read
25 GHSA-w2cx-738m-mc7w PyJWT Public JWK containers accepted as HMAC verification secrets High, 7.4 Full Read
26 GHSA-r2q2-xmpm-7fvh SimpleEval Restricted-expression callable denylist bypass Low Full Read
27 CVE-2026-92403 Secure Custom Fields Unauthenticated post modification via front-end form ID substitution Low, 3.7 Summary-only Read
28 CVE-2026-92400 Payment Gateway for PayPal on WooCommerce Unauthenticated payment bypass via sandbox IPN environment confusion Not displayed by WPScan Summary-only Read
29 CVE-2026-81810 All-in-One WP Migration and Backup Configured export-only user privilege escalation to administrator High, 7.2 Summary-only Read
30 CVE-2026-90922 Paid Member Subscriptions PayPal amount and currency mismatch accepted for paid membership Medium, 5.3 Summary-only Read
31 CVE-2026-85569 Tutor LMS Read-only API key privilege escalation via REST request misclassification High, 7.2 Summary-only Read

Publication state

Twenty-two cases have full technical write-ups based on already-public advisories, commits, releases, and public proof material. Nine cases remain high-level summaries because their coordinators have not yet released the corresponding PoC or sufficient technical detail:

Case Current public gate
WP Compress / CVE-2026-73343 Confirm Patchstack's detailed-release state before publishing private root-cause or PoC material.
BackWPup / CVE-2026-86815 WPScan says the PoC will be displayed September 23, 2026. Re-check the live page before expansion.
Simple Membership / CVE-2026-88764 WPScan says the PoC will be displayed September 25, 2026. Re-check the live page before expansion.
Really Simple Security email 2FA / CVE-2026-89080 WPScan says the PoC will be displayed October 11, 2026. Re-check the live page before expansion.
Secure Custom Fields / CVE-2026-92403 WPScan says the PoC will be displayed October 1, 2026. Re-check the live page before expansion.
Payment Gateway for PayPal on WooCommerce / CVE-2026-92400 WPScan says the PoC will be displayed October 1, 2026. Re-check the live page before expansion.
All-in-One WP Migration and Backup / CVE-2026-81810 WPScan says the PoC will be displayed October 16, 2026. Re-check the live page before expansion.
Paid Member Subscriptions / CVE-2026-90922 WPScan says the PoC will be displayed September 29, 2026. Re-check the live page before expansion.
Tutor LMS / CVE-2026-85569 WPScan says the PoC will be displayed October 14, 2026. Re-check the live page before expansion.

A date passing does not automatically clear a write-up. The coordinator's live public page controls publication. WPScan now displays the PoCs for CVE-2026-17563, CVE-2026-77793, and CVE-2026-75796; those reports were expanded using the public material in this refresh.

Repository layout

Each directory under findings/ represents one distinct vulnerability and contains a public README.md. Cases with both identifiers keep the CVE and GHSA together. The repository intentionally excludes raw private evidence, correspondence, unpublished exploit material, credentials, and embargoed artifacts.

Research standard

The write-ups distinguish:

  • maintainer-published claims from independently verified evidence;
  • affected ranges from directly sampled releases;
  • the demonstrated primitive from conditional downstream impact;
  • vulnerable behavior from negative and fixed controls;
  • finder, reporter, co-reporter, verification, and patch-author roles; and
  • already-public proof material from research that remains withheld.

The goal is a precise account of the failed security boundary, the public impact, and how the remediation restores the intended invariant.

Researcher

Charles Vosburgh — the-vibe-dev

Independent security researcher focused on authorization boundaries, sandbox escapes, parser and deserialization behavior, generated-code injection, WordPress attack surfaces, protocol security, and reproducible vulnerability validation.

Related research tooling

Charles also develops SecHive.ai, an operator-driven security research workbench focused on scoped analysis, reproducible validation, evidence retention, remediation review, and human-controlled disclosure decisions.

Responsible use

Technical material in this repository is intended for defensive analysis, remediation, regression testing, patch verification, and systems the reader owns or is explicitly authorized to assess.

About

Independent vulnerability research by Charles Vosburgh / the-vibe-dev — CVEs, GitHub Security Advisories, technical write-ups, root-cause analysis, remediation, and coordinated disclosure.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors