[{"content":"Hi, I\u0026rsquo;m Antonio, currently an Offensive Security Engineer at Secure Network in Italy. Most of my research interests revolve around the world of application security, from the attack surface of modern applications to everything they depend on. I hold an M.Sc. in Computer Science magna cum laude from Università degli Studi di Milano and I\u0026rsquo;m OSCP certified. Outside of work I spend my time on vulnerability research and bug bounty hunting. If you\u0026rsquo;re interested, here are the publicly disclosed vulnerabilities I\u0026rsquo;ve reported so far.\n","permalink":"https://deturris.io/about/","summary":"About Antonio De Turris","title":"About"},{"content":"Vulnerabilities I have reported and that have been publicly disclosed.\nPrivilege escalation in n8n AI Agents via run_node_tool\nCVE-2026-65015 · Jul 2026 · writeup\n\u0026ldquo;Allowed HTTP Request Domains\u0026rdquo; bypass in the n8n AI Agents MCP connector\nCVE-2026-59207 · Jun 2026 · writeup\nSSRF in the WordPress AI plugin\u0026rsquo;s alt text generation\nGHSA-v2wx-9j88-4rqq · Aug 2026\nStored XSS in Cambium Networks PMP 450b web management interface\nCVE-2026-37243 · Mar 2026\n","permalink":"https://deturris.io/advisories/","summary":"Vulnerabilities reported by Antonio De Turris","title":"Advisories"}]