Don't take documents at face value — detect parser differential attacks in XLSX, PDF, and DOCX
-
Updated
Jun 17, 2026 - Python
Don't take documents at face value — detect parser differential attacks in XLSX, PDF, and DOCX
CVE-2026-85706 — GitLab unauthenticated arbitrary file read (CVSS 10.0). Root-cause analysis, vulnerable Docker lab, and PoC.
Canonically Yours — signing one package, publishing another. Intigriti 0726 write-up. Cross-namespace read via JSON duplicate-key parser differential (Intigriti July 2026)
CHIMERA is a scientific reasoning engine for offensive security. It constructs falsifiable hypotheses about software systems, actively gathers evidence through controlled execution, updates beliefs using structured reasoning, and produces defensible security findings.
Browser demo: real Ed25519 signatures over JSON — showing that a signature binds an exact byte string, never the meaning a parser recovers from it.
To associate your repository with the parser-differential topic, visit your repo's landing page and select "manage topics."