Vulnerabilities I have reported and that have been publicly disclosed.

  • Privilege escalation in n8n AI Agents via run_node_tool
    CVE-2026-65015 · Jul 2026 · writeup

  • “Allowed HTTP Request Domains” bypass in the n8n AI Agents MCP connector
    CVE-2026-59207 · Jun 2026 · writeup

  • SSRF in the WordPress AI plugin’s alt text generation
    GHSA-v2wx-9j88-4rqq · Aug 2026

  • Stored XSS in Cambium Networks PMP 450b web management interface
    CVE-2026-37243 · Mar 2026