<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Wojtek&apos;s Security Blog</title><description/><link>https://blog.wojtek.sh/</link><language>en-us</language><copyright>© 2026 Wojtek Chwala &apos;w0j73k&apos;</copyright><item><title>SMØLLM - Hack.lu 2025</title><link>https://blog.wojtek.sh/blog/hacklu-smollm/</link><guid isPermaLink="true">https://blog.wojtek.sh/blog/hacklu-smollm/</guid><description>Root-cause analysis and exploitation of a format string vulnerability in a C binary (Hack.lu CTF 2025), chained with a stack-based buffer overflow to defeat canary and ASLR/PIE and reach arbitrary code execution via ROP.</description><pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate><category>pwn</category><category>pwn</category><category>hack.lu</category><category>Format String</category><category>ELF</category><author>Wojtek Chwala</author></item><item><title>KONTINUERLIG: From Heredoc Injection to Secret Extraction via GitHub Actions - Hack.lu 2025</title><link>https://blog.wojtek.sh/blog/hacklu-kontinuerlig/</link><guid isPermaLink="true">https://blog.wojtek.sh/blog/hacklu-kontinuerlig/</guid><description>Root-cause analysis and exploitation of a GitHub Actions CI/CD pipeline (Hack.lu CTF 2025). A pull_request_target misconfiguration is leveraged through heredoc injection into GITHUB_ENV, LD_PRELOAD hijacking, and Python module shadowing to cross a privilege boundary. From there, symlink-based Docker build-context manipulation and Problem Matcher abuse chain together to bypass secret redaction and exfiltrate a repository secret.</description><pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate><category>misc</category><category>hack.lu</category><category>Github Actions</category><category>pwnrequest</category><category>LD_PRELOAD hijacking</category><category>heredoc injection</category><author>Wojtek Chwala</author></item><item><title>When Vue Forgets to Escape: From a Missing v-pre to Superadmin Takeover (Part II) - CVE-2025-64112</title><link>https://blog.wojtek.sh/blog/when-vue-forgets-to-escape-cve-2025-64112/</link><guid isPermaLink="true">https://blog.wojtek.sh/blog/when-vue-forgets-to-escape-cve-2025-64112/</guid><description>Part II of the CVE-2025-64112 writeup: weaponizing a stored XSS in the Statamic control panel into full Superadmin takeover. Admin-editable fields are rendered by Vue without v-pre or output encoding, so a {{constructor.constructor(...)}} payload executes JavaScript in a Superadmin&apos;s session. Two proof-of-concept chains are shown — a silent password change on versions ≤5.21.0, and an email swap on 5.22.0 (after password changes were hardened) to hijack the account via password reset.</description><pubDate>Mon, 25 Aug 2025 00:00:00 GMT</pubDate><category>web</category><category>cve</category><category>research</category><category>injection</category><category>privilege escalation</category><author>Wojtek Chwala</author></item><item><title>When Vue Forgets to Escape: Multiple Stored XSS Vectors Caused by Missing v-pre directive</title><link>https://blog.wojtek.sh/blog/when-vue-forgets-to-escape-stored-xss/</link><guid isPermaLink="true">https://blog.wojtek.sh/blog/when-vue-forgets-to-escape-stored-xss/</guid><description>Part I of the CVE-2025-64112 research: multiple stored XSS vectors in the Statamic control panel, rooted in Vue rendering admin-editable fields without the v-pre directive. Because Vue compiles mustache {{ }} expressions client-side, unescaped stored input is treated as executable template code — a {{this.constructor.constructor(&apos;alert(document.cookie)&apos;)()}} payload runs in an admin&apos;s browser. Six control-panel sections (collections, navigation, taxonomies, asset containers, globals, forms) were affected on versions ≤4.42.0. Part II chains this into full Superadmin takeover.</description><pubDate>Tue, 15 Jul 2025 00:00:00 GMT</pubDate><category>web</category><category>cve</category><category>research</category><category>injection</category><category>privilege escalation</category><author>Wojtek Chwala</author></item><item><title>Dyplesher Hack The Box</title><link>https://blog.wojtek.sh/blog/htb-dyplesher/</link><guid isPermaLink="true">https://blog.wojtek.sh/blog/htb-dyplesher/</guid><description>Writeup</description><pubDate>Sat, 07 Nov 2020 00:00:00 GMT</pubDate><category>htb</category><category>amqp</category><category>gogs</category><category>linux</category><category>lua</category><category>memcached</category><category>rabbitmq</category><category>sqlite</category><category>vhosts</category><category>bukkit</category><category>java</category><category>cuberite</category><author>Wojtek Chwala</author></item></channel></rss>