A MITM attacker on the network can silently execute arbitrary shell commands on a Clicky user's machine by forging a single AI tool call in the response stream. No sandbox, no approval prompt, no indication to the user. Plus six more findings, including undisclosed conversation surveillance to a third-party analytics platform.
Outrank.so 2026-05-04
High
Four findings, two of them High, sharing one architectural root cause: authorization enforced in the Next.js app layer, missing from the database tier and from several public API routes. An unauthenticated attacker can hijack a victim's Notion publishing pipeline without ever signing into Outrank.
ParakeetAI 2026-04-01
High embargoed
Coordinated disclosure on an AI interview assistant — writeup embargoed until August 2026
Four findings on an AI assistant for live interviews and meetings — including SSRF via DNS rebinding, CORS null-origin with credentials, and a TOCTOU race on a quota-gated creation flow. Reported privately and fixed under coordinated disclosure. The detailed writeup is embargoed by agreement until approximately August 2026, when it will be republished in full on this site.