Clicky (Humansongs) 2026-05-06
CriticalHigh

Unauthenticated RCE on an unsandboxed macOS AI assistant via SSE tool-call injection

A MITM attacker on the network can silently execute arbitrary shell commands on a Clicky user's machine by forging a single AI tool call in the response stream. No sandbox, no approval prompt, no indication to the user. Plus six more findings, including undisclosed conversation surveillance to a third-party analytics platform.

ParakeetAI 2026-04-01
High embargoed

Coordinated disclosure on an AI interview assistant — writeup embargoed until August 2026

Four findings on an AI assistant for live interviews and meetings — including SSRF via DNS rebinding, CORS null-origin with credentials, and a TOCTOU race on a quota-gated creation flow. Reported privately and fixed under coordinated disclosure. The detailed writeup is embargoed by agreement until approximately August 2026, when it will be republished in full on this site.


Want this for your product?

Before a customer finds it.

A hand-driven audit of your AI-coded SaaS, delivered in 7 days. Starting at $1,500. Find a High or Critical or you don't pay.

See the offer