DEV Community

Santosh Kumar Puppala profile picture

Santosh Kumar Puppala

AI/ML Platform Architect securing production GenAI on Kubernetes · CVE-credited security researcher · creator of Norviq & Veridor.

Joined Joined on 
The POST was guarded, the GET on the same URL was not: cross-tenant PII disclosure in CoopCycle (GET /api/stores/{id}/addresses)

The POST was guarded, the GET on the same URL was not: cross-tenant PII disclosure in CoopCycle (GET /api/stores/{id}/addresses)

Comments
8 min read
The TODO shipped to npm: an unauthenticated route that could stop any city's AI workflow (Your Priorities, @yrpri/api < 9.0.244)

The TODO shipped to npm: an unauthenticated route that could stop any city's AI workflow (Your Priorities, @yrpri/api < 9.0.244)

Comments
7 min read
A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2

A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2

Comments
5 min read
It only guarded the verbs it recognized: a read-only role could cancel invoices in Akaunting

It only guarded the verbs it recognized: a read-only role could cancel invoices in Akaunting

Comments
6 min read
It checked the request, but it changed the composer: FOIA request takeover in MuckRock

It checked the request, but it changed the composer: FOIA request takeover in MuckRock

Comments
7 min read
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

Comments 2
6 min read
The parent check passed, so the forks' secrets shipped anyway — cleartext CI/CD secrets in OneDev (GHSA-p3rv-f672-8x57)

The parent check passed, so the forks' secrets shipped anyway — cleartext CI/CD secrets in OneDev (GHSA-p3rv-f672-8x57)

Comments
7 min read
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

Comments
6 min read
The guard checked the URL, not the record it returned (OpenFn Lightning, GHSA-vf9q-phg3-hqj6)

The guard checked the URL, not the record it returned (OpenFn Lightning, GHSA-vf9q-phg3-hqj6)

Comments
5 min read
How one Owner could take over any account in another company — cross-tenant IDOR in InvoiceShelf (CVE-2026-55610)

How one Owner could take over any account in another company — cross-tenant IDOR in InvoiceShelf (CVE-2026-55610)

Comments
3 min read
One unchecked filename let a popular npm document converter write to any path on disk (CVE-2026-54732)

One unchecked filename let a popular npm document converter write to any path on disk (CVE-2026-54732)

Comments
3 min read
loading...