Sign in

SonarResearch

@sonarresearch.bsky.social
112 followers 0 following 24 posts

Cutting-edge security research by Sonar to educate the world about code security across all software. We're also at @SonarResearch@infosec.exchange 🦣 and @Sonar_Research 🐦

PostsRepliesMedia
SonarResearch @sonarresearch.bsky.social · 22/07/2026
Can folder names be user input? If you interpolate them into a script context! yes. Swift devs often use AppleScript, but it's as dangerous as eval(). Learn about a vulnerability we found in OpenInTerminal: www.sonarsource.com/blog/escape-... #appsec #security #vulnerability
sonarsource.com
Escape from AppleScript: Even folder names can be user input
Learn how an AppleScript injection flaw in OpenInTerminal let crafted folder names execute arbitrary code and how safer APIs prevent similar attacks.
000
SonarResearch @sonarresearch.bsky.social · 07/07/2026
Are your data science tools safe? 🕵️‍♂️ We discovered vulnerabilities in JupyterLab Desktop and the JetBrains Jupyter plugin that can lead to code execution with minimal user interaction. Read the technical details here: www.sonarsource.com/blog/hidden-... #appsec #security #vulnerability
sonarsource.com
More than just data: The hidden security risks in Jupyter notebooks
re your data science tools safe? Sonar researchers uncover vulnerabilities leading to code execution in JupyterLab Desktop and PyCharm.
000
SonarResearch @sonarresearch.bsky.social · 02/06/2026
Shellcode execution as a service! To exploit an argument injection in Jellyfin, we searched and found a gadget in the .NET runtime to turn file writes into code execution. Learn about the bug and this new technique in our blog post: www.sonarsource.com/blog/jellyfi... #appsec #vulnerability
sonarsource.com
Jellyfin RCE | Inconsistent Validation Leads to Argument Injection
Explore a Jellyfin remote code execution flaw where inconsistent validation enables FFmpeg argument injection and unauthenticated code execution.
000
SonarResearch @sonarresearch.bsky.social · 30/04/2026
Can you trust the trust dialog? We discovered that running Claude Code in malicious folders could have executed system commands before the trust dialog even appears! Learn about the details in our latest blog post: www.sonarsource.com/blog/claude-... #appsec #security #vulnerability
sonarsource.com
Arbitrary code execution and Claude Code CLI: How Claude executed code before you click 'trust'
We discovered different ways an untrusted folder can execute arbitrary code in Claude Code before the user is prompted with the trust dialog, allowing for potential compromise when cloning untrusted p...
010
SonarResearch @sonarresearch.bsky.social · 25/03/2026
📱 1-click RCE in the YTDLnis Android app! On Android, turning file writes into RCE is usually quite hard, but here the app had a nice gadget for us. Check out the details in our latest blog post: www.sonarsource.com/blog/ytdlnis... #appsec #security #vulnerability
sonarsource.com
From intent extra to RCE: Argument injection in YTDLnis
Discover a vulnerability our researchers found in the Android app YTDLnis, allowing attackers to execute code on victim devices.
021
SonarResearch @sonarresearch.bsky.social · 18/03/2026
Attending #Insomnihack this week? Don't miss our researcher @pspaul95.bsky.social breaking down various unsafe patterns attackers can abuse to compromise your GitHub Actions workflows!
A speaker graphic for the Swiss Cybersecurity Conference, Insomni'hack, features a grayscale portrait of Paul Gerste alongside details for his session titled 'Zombie Workflows and Other GitHub Actions Horror Stories.' The talk is scheduled for Thursday, 19 March 2026, from 14:30 to 15:20, and will be held in the Cloud session. The graphic includes the Insomni'hack logo and standard conference visual elements on a red background.
010
SonarResearch @sonarresearch.bsky.social · 25/02/2026
Our team is hiring! If you are passionate about finding bugs in code, exploiting them in creative ways, and sharing your findings on our blog, apply here: jobs.lever.co/sonarsource/...
jobs.lever.co
Sonar - Vulnerability Researcher (f/m/d)
Who is Sonar? Sonar helps prevent code quality and code security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experienc...
000
SonarResearch @sonarresearch.bsky.social · 09/12/2025
🧟 A fixed vulnerability that comes back to life? This could have happened in GitHub Actions until yesterday! Learn how attackers could have exploited seemingly fixed workflow vulnerabilities: www.sonarsource.com/blog/zombie-... #appsec #security #vulnerability
sonarsource.com
021
SonarResearch @sonarresearch.bsky.social · 04/11/2025
From bit flip to RCE in Ollama! 🦙 Our latest blog post explains how a file parsing bug led to an interesting out-of-bounds write primitive. Learn how it could have been exploited in Ollama, a tool to run LLMs locally: www.sonarsource.com/blog/ollama-... #security #vulnerability #llm #ai
sonarsource.com
020
SonarResearch @sonarresearch.bsky.social · 15/10/2025
🔄📦 GitHub Actions offer powerful automation capabilities for CI/CD, but they're not immune to attacks. Take a look at how we tackle this risk with SonarQube Cloud by diving into real-world vulnerabilities. www.sonarsource.com/blog/securin... #appsec #security #vulnerability
sonarsource.com
Securing GitHub Actions With SonarQube: Real-World Examples
This blog introduces SonarQube's enhanced analysis capabilities for GitHub Actions, designed to proactively identify and remediate security vulnerabilities like Command Injection and Code Execution th...
000
SonarResearch @sonarresearch.bsky.social · 16/09/2025
Using SonarQube to solve a CTF challenge? Done! ✅ Learn how we detected a 0-day vulnerability during #KalmarCTF, making us first to solve the challenge! From Zip Slip to RCE, using lazy class loading: www.sonarsource.com/blog/code-se... #appsec #CTF #vulnerability
sonarsource.com
031
SonarResearch @sonarresearch.bsky.social · 07/08/2025
🗒️✍️Taking a note on security: our latest blog post focuses on Go vulnerabilities, including Arbitrary File Write, XSS, and Misconfiguration. Showcasing our new support for the language in SonarQube Cloud! www.sonarsource.com/blog/securin... #appsec #security #vulnerability
sonarsource.com
Securing Go Applications With SonarQube: Real-World Examples
Take a deep dive into some vulnerabilities in Go applications and understand how SonarQube Cloud helps developers detect and mitigate them during the development cycle.
010
SonarResearch @sonarresearch.bsky.social · 16/07/2025
📱 Ever wondered what vulnerabilities look like in Android apps? We have 2 real-world examples for you! From simple misconfig to cross-app data flow, learn how vulnerabilities manifest in the Kotlin code of Android apps: www.sonarsource.com/blog/securin... #appsec #security #vulnerability
sonarsource.com
Securing Kotlin Apps With SonarQube: Real-World Examples
Explore how real-world vulnerabilities look in the Kotlin code of Android apps and see how SonarQube helps detect them.
000
SonarResearch @sonarresearch.bsky.social · 08/07/2025
🔓⏫ After compromising every endpoint within an organization, our “Caught in the FortiNet” blog series comes to an end with one more thing. Read more about FortiClient's XPC mistake that allows local privilege escalation to root on macOS: www.sonarsource.com/blog/caught-... #appsec #security
sonarsource.com
Caught in the FortiNet: How Attackers Can Exploit FortiClient to Compromise Organizations (3/3)
In the last blog of this series, we will focus back on FortiClient and learn how the inner workings of this application work, and what crucial mistake happened that led to us uncovering a local privil...
032
SonarResearch @sonarresearch.bsky.social · 01/07/2025
📁🫷🚧Can't control the extension of a file upload, but you want an XSS? Read more on how we overcame this obstacle to further exploit entire organizations using Fortinet endpoint protection: www.sonarsource.com/blog/caught-... #appsec #vulnerability #bugbountytips
sonarsource.com
Caught in the FortiNet: How Attackers Can Exploit FortiClient to Compromise Organizations (2/3)
We recently discovered critical vulnerabilities in Fortinet’s endpoint protection solution that enable attackers to fully compromise organizations with minimal user interaction. In this second article...
011
SonarResearch @sonarresearch.bsky.social · 26/06/2025
🕸️🏢Caught in the FortiNet: Exploiting Fortinet’s endpoint protection solution to compromise an entire organization using minimal user interaction. Dive into our technical analysis of this interesting attack scenario: www.sonarsource.com/blog/caught-... #appsec #security #vulnerability
sonarsource.com
Caught in the FortiNet: How Attackers Can Exploit FortiClient to Compromise Organizations (1/3)
We recently discovered critical vulnerabilities in Fortinet’s endpoint protection solution that enable attackers to fully compromise organizations with minimal user interaction. In the first post of t...
010
SonarResearch @sonarresearch.bsky.social · 24/06/2025
Catch our second talk at #TROOPERS25: 🕸️ Caught in the FortiNet: Compromising Organizations Using Endpoint Protection Yaniv Nizry will tell you the story of multiple vulnerabilities in Fortinet products that can compromise an entire organization, starting with a single click
041
SonarResearch @sonarresearch.bsky.social · 23/06/2025
Coming to #TROOPERS25 this week? We'll be there too, presenting our research! 🎨 Scriptless Attacks: Why CSS is My Favorite Programming Language @pspaul95.bsky.social will convince you why CSS should not be overlooked in client-side web attacks and what is possible without JavaScript today
Title: Scriptless Attacks: Why CSS is My Favorite Programming Language
Speaker: Paul Gerste, Vulnerability Researcher, Sonar
Date: Wednesday, June 25, 2025
Time: 2:15 pm
Location: Track 3
042
SonarResearch @sonarresearch.bsky.social · 10/06/2025
SQL Injection despite using prepared statements? 🧐 Turns out that SQL syntax can be ambiguous! Learn how this has led to vulnerabilities in several popular PostgreSQL client libraries: www.sonarsource.com/blog/double-... #appsec #security #vulnerability
sonarsource.com
Double Dash, Double Trouble: A Subtle SQL Injection Flaw
Can a simple dash character introduce a security risk? Discover how SQL line comments can open the door to unexpected injection vulnerabilities in several PostgreSQL client libraries!
072
SonarResearch @sonarresearch.bsky.social · 20/05/2025
Scripting Outside the Box! 📦 Last week, we saw JS sandboxing pitfalls in API clients. Today, we continue with more complex sandbox escapes in Bruno and Hoppscotch. Learn how they work and how to sandbox JS securely in part 2: www.sonarsource.com/blog/scripti... #appsec #security #vulnerability
sonarsource.com
Scripting Outside the Box: API Client Security Risks (2/2)
Continuing on API client security, we cover more sandbox bypasses, this time in Bruno and Hoppscotch, as well as JavaScript sandboxing best practices.
020
SonarResearch @sonarresearch.bsky.social · 13/05/2025
Ever wondered what's going on behind the scenes of your API client? 🕵️‍♀️ We dug in and found a variety of JS sandboxing pitfalls! Find out how Postman and Insomnia tried to isolate untrusted code and what challenges they faced: www.sonarsource.com/blog/scripti... #appsec #security #vulnerability
sonarsource.com
Scripting Outside the Box: API Client Security Risks (1/2)
Discover hidden risks in API testing tools like Postman and Insomnia. We dive into scripting vulnerabilities and explore JavaScript sandbox security pitfalls.
010
SonarResearch @sonarresearch.bsky.social · 24/04/2025
📊⚠️ Data in danger! We found an XSS vulnerability in Grafana with the help of SonarQube. Learn about the details in our latest blog post: www.sonarsource.com/blog/data-in... #appsec #security #vulnerability
sonarsource.com
Data in Danger: Detecting Cross-Site Scripting in Grafana
Learn how SonarQube detected a Cross-Site Scripting (XSS) vulnerability in Grafana, a popular open-source data observability platform.
032
SonarResearch @sonarresearch.bsky.social · 25/03/2025
🦘🛜 Our second part of the “Diving Into JumpServer” series is live: Read more on how an attacker who bypassed authentication can execute code and fully compromise the JumpServer instance and internal hosts: www.sonarsource.com/blog/diving-... #appsec #security #vulnerability
sonarsource.com
020
SonarResearch @sonarresearch.bsky.social · 20/03/2025
🦘🛜Compromising bastion host to gain full control over the internal infrastructure. Read more about the vulnerabilities we uncovered in JumpServer in our recent blog post: www.sonarsource.com/blog/diving-... #appsec #security #vulnerability
sonarsource.com
Diving Into JumpServer: Attacker’s Gateway to Internal Networks (1/2)
Bastion host offers a centralized point of access and control to an internal network, but what happens when this gateway itself is compromised? In this blog series, we will dive into vulnerabilities w...
030