Research
// vulnerability_research
Vulnerability research, CVE disclosures, and security analyses.
CVE-2022-29078
CVE-2020-8135
EJS, Server side template injection RCE (CVE-2022-29078)
Note: The objective of this research or any similar researches is to improve the nodejs ecosystem security level.
Recently i was working on a related project …
SSRF vulnerability in Uppy, Detected by Shieldfy
In this post, we will explain how Shieldfy detected an SSRF ( Server-side request forgery ) vulnerability in Uppy, one of the popular packages in NPM, diving …