Sign in

Jorian

@jorianwoltjer.com
351 followers 107 following 107 posts

Normalize being weird.

PostsRepliesMedia
Jorian @jorianwoltjer.com · 29/09/2026
We just released the first episode of our new video series: Proof of Concept! Where we explain the vulnerabilities we find at Aikido with visuals and an interview-style. This episode is about the Gogs RCE vulnerability affecting default configuration: youtu.be/QIgr61KhcDo
youtu.be
RCE from a nested repo trick in Gogs!
YouTube video by Aikido Security
020
Jorian @jorianwoltjer.com · 24/09/2026
It finally happened!! Check out the latest @ctbbpodcast.bsky.social episode packed with client-side fun: www.youtube.com/watch?v=eV81...
youtube.com
Browser Logic Errors & XS-Leaks with Jorian Woltjer (Ep. 193)
YouTube video by Critical Thinking - Bug Bounty Podcast
010
Jorian @jorianwoltjer.com · 30/08/2026
🇳🇱 Voor de Nederlanders, ik help mee met het organiseren en challenges bouwen bij de National Hackers Cup 2026! Kom 19 september naar Purmerend, we hebben plek voor 500 deelnemers. Zoek een team van 4 of ga solo, en meld je aan: nhc.sh/aanmelden
nhc.sh
National Hackers Cup 2026 | Het NK Hacken | 19 september, Purmerend
De grootste CTF in de geschiedenis van Nederland. Zaterdag 19 september 2026 in het H20 Esports Campus in Purmerend. 500 plekken, gratis, en de winnaar gaat naar huis als beste hacker van het land.
000
Jorian @jorianwoltjer.com · 20/08/2026
There's never enough Unauthenticated RCE's. Here I took a limited AI finding and through some clever Git structures, escalate it to Remote Code Execution on the default installation of Gogs 0.14.2! Read this and more in our latest blog post: www.aikido.dev/blog/fixed-r...
aikido.dev
Yet another RCE in Gogs, but it's fixed this time!
CVE-2026-52813 | An Aikido pentesting agent flagged a path traversal in Gogs. We escalated it to full RCE and reported two more bugs, all fixed in 0.14.3.
010
Reposted by Jorian
Cezar Lungu @cezarlungu.com · 17/08/2026
shaderghost.gg
shaderghost.gg
ShaderGhost — the tracking ID you can't delete
Clear your cookies. It's still watching. See a tracking ID hidden in your graphics card, live in your browser.
021
Jorian @jorianwoltjer.com · 09/08/2026
What started with a simple question on Discord, ended in *reviving an old XS-Leak technique* for probing status codes in background requests! Unravel the mystery with me in the latest @ctbbpodcast.bsky.social blog post: lab.ctbb.show/research/sol...
https://lab.ctbb.show/research/solving-an-orb-mystery
022
Jorian @jorianwoltjer.com · 03/08/2026
Playing L3akCTF this weekend with my teammates in Superflat was a blast! The challenge that stood out to me was "Squid", showcasing a werkzeug Race Condition with file descriptor symlinks that I'm sure can be applied elsewhere. Check out the writeup below: jorianwoltjer.com/blog/p/ctf/l...
jorianwoltjer.com
L3akCTF 2026 - Squid | Jorian Woltjer
A complex server-side web challenge showing off some parser differentials and a new technique. It was followed by a really interesting race condition technique involving file descriptors to read envir...
010
Jorian @jorianwoltjer.com · 22/07/2026
We took a look at popular open-source forum platform NodeBB! This resulted in interesting vulnerabilities involving the ActivityPub protocol My favorite is *translation templates* causing XSS everywhere, requiring a large rewrite of the codebase in v4.14.0 www.aikido.dev/blog/eight-h...
aikido.dev
Finding eight high-severity vulnerabilities in NodeBB in six hours
Eight high-severity NodeBB vulnerabilities, found by our AI Pentest in six hours. Full technical breakdown of the XSS chains, auth bypasses, and post hijacking.
012
Jorian @jorianwoltjer.com · 07/07/2026
Simple IDOR turned into an interesting question of "how do we find the IDs?" The answer: Continuously probe ObjectId()'s from MongoDB and search through the predictable gaps! Check out the full explanation & implementation below: www.aikido.dev/blog/predict...
aikido.dev
Predicting MongoDB ObjectId() continuously in Rocket.Chat
Aikido's AI pentester found this file-access flaw in Rocket.Chat. A closer look at MongoDB's ObjectId() showed the weak randomness that makes it exploitable.
021
Jorian @jorianwoltjer.com · 03/07/2026
It's friday so you know what that means, time for a critical vulnerability! Okay... we announced it 4 weeks ago already to be fair, but now we can talk about the technical parts 🙌 Read how authentication could be bypassed on every online phpBB instance: www.aikido.dev/blog/authent...
aikido.dev
Authentication Bypass in the default configuration phpBB
Our AI pentest agents found a critical phpBB auth bypass (CVE-2026-48611): one unauthenticated request logs you into any account. See the exploit and the fix.
111
Jorian @jorianwoltjer.com · 03/07/2026
This new HTML feature just shipped in Chrome 150, it's gonna be veeeeery interesting 👀 github.com/WICG/declara...
https://yeswehack.github.io/Dom-Explorer/shared?id=860dd7e8-6ae1-41c6-9f06-68beb03e101c
121
Jorian @jorianwoltjer.com · 02/06/2026
Now that everybody's had a chance to solve it, here's a timelapse of my playtesting run of the JavaScript Crossword! SPOILER WARNING: Please try it yourself first in the post below, it's very satisfying to solve, I don't want you to miss out on that 😄 (1 second = 2 minutes)
052
Jorian @jorianwoltjer.com · 28/05/2026
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)
jorianwoltjer.com
Finding XSS on Shazzer (literally) | Jorian Woltjer
How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...
096
Reposted by Jorian
Rebane @rebane2001.bsky.social · 25/05/2026
i made a new game called js crossword where you have to solve it by literally writing javascript code that eval()'s into the correct values! check it out if you're into ctfs or wanna challenge your javascript skills lyra.horse/fun/jscrossw... <3
JS Crossword
a crossword where the clue = eval(answer)

Welcome to JS Crossword! Every clue is a JS eval of its answer - for example, 7 could be solved with 3+4 and [object Object] could be solved with []+{}. This crossword uses some lesser-known and cursed JS features, so I'd recommend it for people already somewhat familiar with JavaScript.

You're allowed to use the following characters: A-Za-z0-9!"()*+-./<=>[]`{}. This means that no spaces (empty squares), commas, or semicolons are allowed to be used. The crossword is case-sensitive. The final answer consists only of english words, so it must match A-Za-z.

Your answers will be evaluated within an eval() sandbox, you can try it out at the playground below. You're of course also allowed to use other resources, such as DevTools, MDN, searching etc. This crossword is human-made, so if you solve it with AI you're lame, learn to have fun.

You can change the writing direction by clicking a square or pressing ctrl. Your progress is savedbanner image - JS Crossword, a crossword where the clue = eval(answer)

a mini-crossword is pictured underneath as a visual examplegameplay screenshot showing the crossword partially filled in

the status at the bottom can be seen saying:
across (green)
expect: cw==
actual: cw==
down (red)
expect: -Infinity
error: SyntaxError: Unexpected end of input
2322358
Jorian @jorianwoltjer.com · 08/05/2026
Thanks @cryptocat.me for inviting me to my first ever podcast! Check out the section at 29:36 😄
030
Jorian @jorianwoltjer.com · 03/05/2026
Happy to have made some web chllaenges for Plfanzen CTF. The evetn runs next weekend, cehck it out! plfanzen.lol
plfanzen.lol
plfanzen
011
Jorian @jorianwoltjer.com · 23/04/2026
Cool exploit with @0x999.net: He found that \x7F breaks Chrome's "Copy as cURL (cmd)" command parsing in Windows Console Host. In combination with a ", it allowed you to add any arguments to curl. With -o writing files is easy, but we need the username for the startup path... (1/2)
Windows shell:startup folder wrote shell.bat from conhost.exe opening calculator. Username in path highlighted
161
Jorian @jorianwoltjer.com · 21/04/2026
We tested another mail client, Roundcube this time. The agents found a Stored Self-XSS vulnerability that could really only be exploited with Cookie Tossing. Scary for password reset tokens... Blog post below: www.aikido.dev/blog/roundcu...
aikido.dev
Roundcube XSS chained with cookie tossing for full inbox access
We found a stored XSS in Roundcube's draft attachment endpoint that, chained with a cookie tossing technique, gives an attacker full access to a victim's inbox. Here's how the exploit chain works and ...
041
Jorian @jorianwoltjer.com · 17/04/2026
New blog post is out! A few vulnerabilities in Mailcow. A critical unauthenticated XSS, and another interesting Self-XSS escalation involving a Login CSRF with a leftover tab. Check it out: www.aikido.dev/blog/xss-vul...
aikido.dev
Multiple XSS Vulnerabilities Found in Mailcow, Including Unauthenticated Account Takeover
Aikido's AI pentest agent found three XSS vulnerabilities in Mailcow, one of which let unauthenticated attackers take over administrator accounts. All issues have been patched as of version 2026-03b.
011
Jorian @jorianwoltjer.com · 17/03/2026
Fun parser differential to fallback SVG sanitizer bypass: github.com/freescout-he...
github.com
Stored XSS through SVG file upload with filter bypass
### Summary Bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of `.png` with content type of `imag...
032
Jorian @jorianwoltjer.com · 04/03/2026
WebSockets are not yet affected by Local Network Access permission in Chrome. Check out this blog post from my colleague Robbe! www.aikido.dev/blog/storybo...
aikido.dev
How Storybook's WebSocket Server Became a Supply Chain Attack Vector: CVE-2026-27148
CVE-2026-27148 exposes a WebSocket hijacking flaw in Storybook that can escalate into supply chain compromise. Learn the attack path, impact, and how to remediate.
040
Jorian @jorianwoltjer.com · 02/03/2026
XSS on a password manager, about the scariest impact you can have... github.com/aliasvault/a... Luckily it was fixed super quick! Here's a simple script you can use to send raw HTML in emails. I think a lot more clients will benifit from sanitizer testing. gist.github.com/JorianWoltje...
github.com
Cross-Site Scripting (XSS) via Email HTML Rendering
## Impact A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an ali...
011
Reposted by Jorian
aikido | no bullsh*t security for devs @aikidosecurity.bsky.social · 26/02/2026
Software can now secure itself. → www.aikido.dev/attack/infin...
131
Jorian @jorianwoltjer.com · 23/02/2026
Just a few days later, there's the next blog post for @aikidosecurity.bsky.social! Another framework-level vulnerability this time affecting Astro, resulting in SSRF if an unvalidated connection can be made to the webserver. Read the details here: www.aikido.dev/blog/astro-f...
aikido.dev
Astro SSRF Vulnerability: Host Header Injection in SSR Error Pages (CVE-2026-25545)
Aikido Security's AI pentesting agent discovered a Server-Side Request Forgery vulnerability in Astro's SSR implementation. Learn how Host header injection in prerendered error pages allowed full inte...
010
Jorian @jorianwoltjer.com · 19/02/2026
My first disclosed vulnerability since joining @aikidosecurity.bsky.social, and it's a banger! SvelteKit + Vercel = Cache Deception. This shows how AI agents can find framework-level vulnerabilities, and that caching will continue to cause headaches. Enjoy :) www.aikido.dev/blog/sveltes...
aikido.dev
SvelteSpill: Critical Cache Deception Bug in SvelteKit + Vercel
SvelteSpill is a cache deception vulnerability affecting default SvelteKit apps deployed on Vercel. Authenticated responses can be cached and exposed across users. Learn how to check if you’re vulnera...
171
Jorian @jorianwoltjer.com · 01/02/2026
Had a fun XSS gadget chain with antoniusblock on a real world target, he made an awesome writeup: blog.antoniusblock.net/posts/dom-cl...
blog.antoniusblock.net
A CTF-Style XSS Chain in the Wild: DOM Clobbering, Gadgets, and CSP Bypass
A bug bounty target that unexpectedly felt like a CTF. What began as simple recon turned into a nice chain of discoveries that ultimately led to a valid XSS
092
Jorian @jorianwoltjer.com · 15/01/2026
Every year I look through this list with amazement for what all the people came up with. This year I suddenly saw my own article nominated, not 1 but 2! 🤩 1. "Nonce CSP bypass using Disk Cache" on my blog 2 "Stopping Redirects" with @ctbbpodcast.bsky.social Go vote! portswigger.net/polls/top-10...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.
030
Jorian @jorianwoltjer.com · 05/01/2026
I made a shorter writeup for the CatGPT challenge during hxp CTF at 39C3! It featured a cool combination of JavaScript injections to escape our context and fix the remaining syntax. Check it out: jorianwoltjer.com/blog/p/ctf/h...
jorianwoltjer.com
hxpCTF 2025 - CatGPT | Jorian Woltjer
The hardest web challenge during 39C3's hxp CTF. Auditing RegExes in a PHP library to uncover small gadgets that allow escaping and fixing a JavaScript context.
051
Jorian @jorianwoltjer.com · 27/12/2025
Just arrived at #39c3, shoot me a DM if you wanna meet! 😄
011
Jorian @jorianwoltjer.com · 23/12/2025
Here is my writeup of Intigriti's December XSS challenge. It consisted of 6 smaller challenges combining into a big 1-click exploit. One of the most fun ones I've ever played. Loved the unique format by @renwax23.bsky.social! jorianwoltjer.com/blog/p/ctf/i...
jorianwoltjer.com
Intigriti December XSS Challenge (1225) | Jorian Woltjer
A unique 6-part challenge by @Renwa containing many interesting techniques that combine into one large exploit. Learn some HTML/JavaScript quirks, an XS-Leak and how to minimize user interaction
031
Jorian @jorianwoltjer.com · 09/12/2025
There's a new post on the Critical Research Lab! I've seen a lot of questions and fun tricks related to this subject recently so I hope this helps answer some of them. Enjoy! lab.ctbb.show/research/sto...
lab.ctbb.show
Stopping Redirects
Interesting ways to stop redirects of another site in the browser for use in OAuth and exploits requiring interaction
010
Reposted by Jorian
Rebane @rebane2001.bsky.social · 04/12/2025
my new blogpost is out!! this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration and i've already used it to get a google docs bounty ^^ have fun <3 lyra.horse/blog/2025/12...
lyra.horse
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
818150
Jorian @jorianwoltjer.com · 16/11/2025
Really interesting technique from a local CTF. In gunicorn with --proxy-protocol --proxy-allow-from='*', the "Proxy Protocol" (github.com/haproxy/hapr...) allows you to spoof the source IP with a PROXY prefix like this! I feel like it might be useful as impact in Request Tunneling👀
PROXY TCP4 127.0.0.1 1.2.3.4 1337 80
GET /ip HTTP/1.1
Host: 1.2.3.4:80

------------------------------------
HTTP/1.1 200 OK
Server: gunicorn

Your IP: 127.0.0.1
130
Jorian @jorianwoltjer.com · 17/10/2025
For the people who don't have time to read this entire thing, here are the coolest tricks I mentioned 😄: (1/5)
131
Jorian @jorianwoltjer.com · 13/10/2025
Follow your rabbit holes is the takeaway from my latest CTF writeup. I found several interesting techniques that can help tricky situations, such as using the Connection Pool to make Client-Side Race Conditions easier! Read the whole thing on my blog: jorianwoltjer.com/blog/p/ctf/o...
jorianwoltjer.com
openECSC 2025 - kittychat-secure | Jorian Woltjer
Overcomplicating a hard client-side web challenge involving complex CSP script gadgets. Exploit Math.random() predictability, and learn how to use the Connection Pool to make Race Conditions easier.
032
Jorian @jorianwoltjer.com · 08/10/2025
I posted 2 more small articles to the Critical Thinking Research Lab: * Nonce CSS leak in MathML: lab.ctbb.show/research/lea... * HTML fun facts: lab.ctbb.show/research/htm...
lab.ctbb.show
Leaking CSP nonces with CSS & MathML
By dangling a tag in HTML, leaking nonce attributes via CSS is possible again!
051
Jorian @jorianwoltjer.com · 19/09/2025
My first post for the @ctbbpodcast.bsky.social Research Lab is live. Super excited to be part of this team, can't wait to see what crazy research is gonna come from this! lab.ctbb.show/research/Exp...
lab.ctbb.show
Exploiting Web Worker XSS with Blobs
Ways to turn XSS in a Web Worker into full XSS, covering known tricks and a new generic exploit using Blob URLs with the Drag and Drop API
093
Jorian @jorianwoltjer.com · 18/09/2025
AMAZING technique by @salvatoreabello, I've been inspired by the connection pool exploits he comes up with. Check out this crazy impact labeled as "working as intended": blog.babelo.xyz/posts/cross-...
063
Jorian @jorianwoltjer.com · 16/09/2025
While playing a challenge by Salvatore Abello, I found a pretty interesting way to exploit Dangling Markup with a strict CSP. All you need is an <iframe>, <object> or <embed> set to about:blank, with a dangling name= attribute. This vulnerable page should be iframable.
Content-Security-Policy: default-src 'none'

<object data="about:blank" name='
<form>
  <input type="hidden" name="csrf" value="SECRET">
</form>
<script>
  console.log('Hello, world!');
</script>
210
Jorian @jorianwoltjer.com · 13/09/2025
@omidxrz.bsky.social shared this nice postMessage() challenge some time ago. I'm a bit late, but worth trying if you haven't already :D Otherwise, my solution is below, it's a really fun technique that makes me re-evaluate all the .source checks I've seen before...
<!DOCTYPE html>
<html>
<body>
  <h1>Impossible</h1>
  <div id="output">Waiting for messages...</div><br>
  <button id="loadIframeButton">Load Message Frame</button>
  <script>
    document.getElementById('loadIframeButton').addEventListener('click', () => {
      const iframe = document.createElement('iframe');
      iframe.id = 'message_frame';
      iframe.srcdoc = '<html><body><script>window.parent.postMessage("document.body.innerHTML = \'<h1>Impossible Message</h1>\'", "*");<\/script></body></html>';
      iframe.style.display = 'none';
      document.body.appendChild(iframe);
    });
  </script>
  <script>
    window.onmessage = function (event) {
      if (event.source != window.message_frame?.contentWindow || window !== window.top) {
        document.getElementById('output').innerHTML = "No Hacker!";
        return;
      }

      document.getElementById('output').innerHTML = "received";
      const result = eval(event.data);
    };
  </script>
</body>
</html>
130
Jorian @jorianwoltjer.com · 27/08/2025
The last Intigriti challenge by @0xblackbird was a fun combination of SSRF to RCE using a surprisingly exploitable pitfall in NextJS middleware. Check out my writeup below: jorianwoltjer.com/blog/p/ctf/i...
jorianwoltjer.com
Intigriti August RCE Challenge (0825) | Jorian Woltjer
A challenge to achieve RCE through SSRF by @0xblackbird, involving an interesting NextJS middleware pitfall. We build a clean proxy for it and find some extra vulnerabilities along the way.
0101
Jorian @jorianwoltjer.com · 01/08/2025
#bugbountytips Template Injection payload list: {{7*7}} ${7*7}} 49 <%=7*7%>
331
Jorian @jorianwoltjer.com · 19/07/2025
I made a hard @intigriti.com XSS challenge this July 😅 But, it involves some very interesting Mutation XSS & DOM Clobbering fun combined with a CSP Bypass using the powerful SocketIO gadget. Everything's explained in my writeup below! jorianwoltjer.com/blog/p/ctf/i...
jorianwoltjer.com
Intigriti July XSS Challenge (0725) | Jorian Woltjer
My author's writeup of the July 2025 challenge. Perform Mutation XSS to DOM Clobber an change the insertion point into an iframe, then bypass the CSP using a new useful Socket.IO gadget
071
Jorian @jorianwoltjer.com · 02/07/2025
Here's my writeup the technique allowing some nonce-based CSPs to be bypassed. I think it definitely has some practical use, so included some details about different scenario's. Don't let that HTML-injection of yours wait! jorianwoltjer.com/blog/p/resea...
jorianwoltjer.com
Nonce CSP bypass using Disk Cache | Jorian Woltjer
The solution to my small XSS challenge, explaining a new kind of CSP bypass with browser-cached nonces. Leak it with CSS and learn about Disk Cache to safely update your payload
3155
Jorian @jorianwoltjer.com · 30/06/2025
Just found an interesting way to bypass some nonce-based CSPs and made a small XSS challenge with an exploitable scenario. See if you can find it before I tell! Source JS: gist.github.com/JorianWoltje... URL: greeting-chall.jorianwoltjer.com Found a solution? Please DM to avoid spoilers, thanks!
160
Jorian @jorianwoltjer.com · 27/06/2025
This is a Public Service Announcement to all client-side challenge authors: *XSS on any localhost origin makes RCE possible on selenium!*
030
Jorian @jorianwoltjer.com · 27/06/2025
This month @ToG gave us an unusual, but very cool challenge. It required some messing with a headless browser via Arbitrary File Write, and then to use a little-known Chromedriver CSRF → RCE trick. A must-know for challenge-cheesers like myself! jorianwoltjer.com/blog/p/ctf/i...
jorianwoltjer.com
Intigriti June RCE Challenge (0625) | Jorian Woltjer
A surprising RCE challenge instead of XSS, created by @ToG. I took an unintended approach involving the Preferences file and a chromedriver CSRF RCE issue, a must-know for CTF authors.
130
Jorian @jorianwoltjer.com · 18/06/2025
Many great techniques covered in this writeup by @rewhile for different cheesy 🧀 strategies and client-side fun. Show them some love! I promise you'll learn something new: t.co/hox8lncSEN
t.co
https://rewhile.github.io/posts/smiley-2025/
030
Jorian @jorianwoltjer.com · 13/06/2025
Small tip for the JavaScript reverse engineers out there, Chrome has a `debug()` function which triggers a breakpoint whenever its first argument is called. It even works on built-in methods, no more wrapping stuff in proxies :D debug(DOMParser.prototype.parseFromString)
0111
Jorian @jorianwoltjer.com · 05/06/2025
Just pushed a new frontend for my site, and a new post! This one's about an tricky file write vulnerability on Windows in OBS. By crafting an image with very specific pixels, we can plant a backdoor on your PC all from an attacker's site by misconfiguring: jorianwoltjer.com/blog/p/resea...
jorianwoltjer.com
OBS WebSocket to RCE | Jorian Woltjer
Disabling password authentication of your OBS WebSocket server can have devastating consequences. We'll attack from the browser to construct an RCE payload on Windows formed from the pixels of an imag...
152