<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>0x5t - Security Research</title>
    <link>https://0x5t.raptx.org</link>
    <description>Security research and CTF writeups by 0x5t (RaptX).</description>
    <language>en-us</language>
    <image>
      <url>https://0x5t.raptx.org/assets/logo.png</url>
      <title>0x5t</title>
      <link>https://0x5t.raptx.org/</link>
    </image>
    <lastBuildDate>Tue, 25 Mar 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://0x5t.raptx.org/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>CVE-2026-22558</title>
      <link>https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b</link>
      <guid isPermaLink="true">https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b</guid>
      <pubDate>Tue, 18 Mar 2026 00:00:00 GMT</pubDate>
      <description>Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.</description>
      <category>CVE</category>
      <category>NoSQL Injection</category>
      <category>Privilege Escalation</category>
      <category>UniFi</category>
    </item>
    <item>
      <title>CVE-2026-25635: Calibre CHM Path Traversal to RCE</title>
      <link>https://0x5t.raptx.org/posts/calibre-chm-rce.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/calibre-chm-rce.html</guid>
      <pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate>
      <description>Path traversal vulnerability in Calibre 9.1.0's CHM reader allows arbitrary file writes and code execution by dropping payloads into the Windows Startup folder.</description>
      <category>CVE</category>
      <category>RCE</category>
      <category>Path Traversal</category>
      <category>Calibre</category>
    </item>
    <item>
      <title>CVE-2026-25636: Calibre EPUB Path Traversal to RCE</title>
      <link>https://0x5t.raptx.org/posts/calibre-epub-rce.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/calibre-epub-rce.html</guid>
      <pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate>
      <description>Path traversal vulnerability in Calibre 9.1.0's EPUB conversion allows arbitrary file corruption and code execution via malicious ebook files.</description>
      <category>CVE</category>
      <category>RCE</category>
      <category>Path Traversal</category>
      <category>Calibre</category>
    </item>
    <item>
      <title>CVE-2026-26065</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26065</link>
      <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26065</guid>
      <pubDate>Wed, 19 Feb 2026 00:00:00 GMT</pubDate>
      <description>Critical path traversal vulnerability in Calibre's PDB file readers (both 132-byte and 202-byte variants) allows arbitrary file writes with arbitrary extension and content anywhere the user has write permissions, enabling code execution or denial of service. Affects versions up to 9.2.1, fixed in 9.3.0.</description>
      <category>CVE</category>
      <category>Path Traversal</category>
      <category>Calibre</category>
      <category>PDB</category>
    </item>
    <item>
      <title>CVE-2026-26064</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26064</link>
      <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26064</guid>
      <pubDate>Wed, 19 Feb 2026 00:00:00 GMT</pubDate>
      <description>Critical path traversal vulnerability in Calibre's extract_pictures() function fails to sanitize '..' sequences, allowing arbitrary file writes anywhere the user has write permissions. On Windows, attackers can achieve RCE by writing payloads to the Startup folder. Affects versions up to 9.2.1, fixed in 9.3.0.</description>
      <category>CVE</category>
      <category>Path Traversal</category>
      <category>RCE</category>
      <category>Calibre</category>
    </item>
    <item>
      <title>CVE-2026-26075</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26075</link>
      <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26075</guid>
      <pubDate>Wed, 19 Feb 2026 00:00:00 GMT</pubDate>
      <description>Server-side request forgery vulnerability in FastGPT's web page acquisition and HTTP nodes allows exploitation through insufficient internal network address detection. Fixed in version 4.14.7.</description>
      <category>CVE</category>
      <category>SSRF</category>
      <category>FastGPT</category>
      <category>AI Security</category>
    </item>
    <item>
      <title>Ghost Board Writeup</title>
      <link>https://0x5t.raptx.org/posts/ghost-board-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/ghost-board-writeup.html</guid>
      <pubDate>Sun, 25 Jan 2026 00:00:00 GMT</pubDate>
      <description>Ghost Board is a web application built with Spring Boot and AngularJS that involves AngularJS CSTI, Thymeleaf SSTI, and H2 database exploitation to read the flag.</description>
      <category>CTF</category>
      <category>Web Exploitation</category>
      <category>SSTI</category>
      <category>0xL4ugh</category>
    </item>
    <item>
      <title>0xNote Writeup</title>
      <link>https://0x5t.raptx.org/posts/0xnote-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/0xnote-writeup.html</guid>
      <pubDate>Sun, 25 Jan 2026 00:00:00 GMT</pubDate>
      <description>A PHP-based note-taking application with a premium color customization feature protected by nginx. Exploitation involves nginx bypass, arbitrary class instantiation, and CVE-2024-2961 for RCE.</description>
      <category>CTF</category>
      <category>Web Exploitation</category>
      <category>PHP</category>
      <category>0xL4ugh</category>
    </item>
    <item>
      <title>CVE-2026-25130</title>
      <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25130</link>
      <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25130</guid>
      <pubDate>Wed, 30 Jan 2026 00:00:00 GMT</pubDate>
      <description>Critical command injection vulnerability (CVSS 9.7) discovered in the CAI (Cybersecurity AI) framework. The vulnerability allows Remote Code Execution through argument injection in the find_file agent tool, exploitable via prompt injection.</description>
      <category>CVE</category>
      <category>Command Injection</category>
      <category>AI Security</category>
      <category>RCE</category>
    </item>
    <item>
      <title>OSCP+</title>
      <link>https://www.offensive-security.com/courses/oscp/</link>
      <guid isPermaLink="true">https://www.offensive-security.com/courses/oscp/</guid>
      <pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate>
      <description>Offensive Security Certified Professional is an ethical hacking certification offered by Offensive Security that teaches penetration testing methodologies and the use of the tools included with the Kali Linux distribution.</description>
      <category>Certification</category>
      <category>OSCP</category>
      <category>Offensive Security</category>
      <category>Penetration Testing</category>
    </item>
    <item>
      <title>Scepter Writeup</title>
      <link>https://0x5t.raptx.org/posts/scepter-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/scepter-writeup.html</guid>
      <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
      <description>A hard Active Directory machine involving NFS share exploitation, certificate abuse, and multiple chained DACL vulnerabilities leading to full domain compromise through ADCS misconfigurations.</description>
      <category>HackTheBox</category>
      <category>Windows</category>
      <category>Active Directory</category>
    </item>
    <item>
      <title>Haze Writeup</title>
      <link>https://0x5t.raptx.org/posts/haze-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/haze-writeup.html</guid>
      <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
      <description>A hard Windows machine exploiting Splunk Arbitrary File Read vulnerability for initial access, leveraging Active Directory for lateral movement, and abusing SeImpersonatePrivilege for SYSTEM shell access.</description>
      <category>HackTheBox</category>
      <category>Windows</category>
      <category>Splunk</category>
    </item>
    <item>
      <title>Down Writeup</title>
      <link>https://0x5t.raptx.org/posts/down-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/down-writeup.html</guid>
      <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
      <description>An easy machine exploiting an arbitrary file read vulnerability to achieve remote code execution and privilege escalation through a user's sudo permissions.</description>
      <category>HackTheBox</category>
      <category>Linux</category>
      <category>RCE</category>
    </item>
    <item>
      <title>Cypher Writeup</title>
      <link>https://0x5t.raptx.org/posts/cypher-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/cypher-writeup.html</guid>
      <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
      <description>A medium-difficulty machine involving Cypher injection for authentication bypass, command injection in a custom Java method, and privilege escalation through sudo misconfiguration on the bbot utility.</description>
      <category>HackTheBox</category>
      <category>Linux</category>
      <category>Cypher</category>
    </item>
    <item>
      <title>Code Writeup</title>
      <link>https://0x5t.raptx.org/posts/code-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/code-writeup.html</guid>
      <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
      <description>An easy Linux machine featuring remote code execution in a Python code editor web application and privilege escalation through SQLite credential cracking and command injection.</description>
      <category>HackTheBox</category>
      <category>Linux</category>
      <category>RCE</category>
    </item>
    <item>
      <title>Cicada Writeup</title>
      <link>https://0x5t.raptx.org/posts/cicada-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/cicada-writeup.html</guid>
      <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
      <description>An easy Active Directory Windows machine demonstrating a classic domain compromise chain through SMB share enumeration, credential extraction, password spraying, and SeBackupPrivilege abuse.</description>
      <category>HackTheBox</category>
      <category>Windows</category>
      <category>Active Directory</category>
    </item>
    <item>
      <title>Cap Writeup</title>
      <link>https://0x5t.raptx.org/posts/cap-writeup.html</link>
      <guid isPermaLink="true">https://0x5t.raptx.org/posts/cap-writeup.html</guid>
      <pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate>
      <description>An easy Linux machine demonstrating an insecure direct object reference vulnerability in an HTTP server for network traffic captures, exploitable through plaintext FTP credentials.</description>
      <category>HackTheBox</category>
      <category>Linux</category>
      <category>IDOR</category>
    </item>
    <item>
      <title>Deep Dive - CVE-2025-31324</title>
      <link>https://github.com/0x5t/DeepDives/tree/main/CVE-2025-31324</link>
      <guid isPermaLink="true">https://github.com/0x5t/DeepDives/tree/main/CVE-2025-31324</guid>
      <pubDate>Mon, 25 Aug 2025 00:00:00 GMT</pubDate>
      <description>SAP NetWeaver Visual Composer Unauthenticated File Upload vulnerability analysis.</description>
      <category>CVE</category>
      <category>RCE</category>
      <category>File Upload</category>
    </item>
  </channel>
</rss>
