writeups.xyz writeups.xyz / Vladimir Metnew (@Vladimir_metnew)

Title Vulnerabilities Programs Authors
[UNPATCHED] Cli: gh run download implementation allows overwriting git repository configuration upon artifacts downloading
RCE in GitHub Desktop < 2.9.4
Exploiting popular macOS apps with a single “.terminal” file.
Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution.
3 XSS in ProtonMail for iOS