Skip to content
View Aviral2642's full-sized avatar

Block or report Aviral2642

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Aviral2642/README.md
Aviral Srivastava
Pwnie Awards 2026 Nominee LinkedIn Medium HackerNoon Sessionize HackTheBox CISA KEV
Pwnie Awards 2026 — Nominee, Best Server-Side / Cloud Bug

◈ PWNIE AWARDS 2026 — NOMINEE

BEST SERVER-SIDE / CLOUD BUG · for CVE-2026-33017 · announced at DEF CON 34, Las Vegas

The Pwnies are the closest thing offensive security has to an industry ballot — the bugs your peers thought were the best work of the year. CVE-2026-33017 was nominated for Best Server-Side / Cloud Bug in 2026. It didn't take the statue at DEF CON 34. The nomination is the part I keep.

▸ The bug

An unauthenticated exec() sink reachable from Langflow's public flow endpoint. No credentials, no chained primitive, no exotic preconditions — one request to a documented route and you are running code on the orchestrator.

▸ Why it mattered

Langflow sits underneath the AI stack — it holds model credentials, vector-store keys, and tool-call permissions. Compromising the orchestrator compromises everything it orchestrates. CVSS 9.3 CRITICAL.

▸ What happened next

Added to the CISA KEV catalog. Exploited in the wild within 20 hours of disclosure. Covered by The Hacker News, Help Net Security, Infosecurity, Sysdig, and Qualys — quoted by name as the discoverer.

Writeups: Medium · HackerNoon · Advisory GHSA-vwmf-pq79-vjvx · NVD

root@aviral — whoami

Assigned CVEs

▓ The 2026 Batch — Breaking Agentic Workflow Platforms

Four CVEs across two orchestrators, all landing on the same seam: the gap between "we validated this input" and "we already ran it."

CVE Target Finding Severity Advisory · Fix
CVE-2026-69258 Flowise Unauthenticated property injection — the Prediction API spreads overrideConfig into the flow execution context with no allow-list, so an attacker controls internals the flow assumed were server-owned 8.8 HIGH CVSS 4.0
CWE-639 · CWE-915
GHSA-6vh2-wg4h-4vwj
fixed in flowise@3.1.3
CVE-2026-73081 Activepieces OS command injection — the worker builds a Code step's on-disk path from the step name and hands it to a shell-invoked build command. Shell metacharacters execute during compilation, before any sandbox exists 8.7 HIGH CVSS 4.0
CWE-78
GHSA-3pfv-m69p-5fv5
fixed in 0.80.0
CVE-2026-73083 Activepieces Sandbox escape — in SANDBOX_CODE_ONLY mode the engine loads the compiled module via importFresh() (a require() wrapper) before the V8 isolate is applied. Top-level code reaches child_process, fs, and AP_ENCRYPTION_KEY 7.6 HIGH CVSS 4.0
CWE-693
GHSA-gr3h-c2j7-r52g
fixed in 0.80.0
CVE-2026-73084 Activepieces XSS in the OAuth callback — /api/redirect embeds the attacker-supplied code parameter into an inline <script> unescaped. Unauthenticated script execution in the app origin against any logged-in victim 6.1 MEDIUM CVSS 3.1
CWE-79
GHSA-hc39-cm5m-q8g7
fixed in 0.83.0

All four assigned via the GitHub CNA. Flowise writeup: Flowise patched overrideConfig. I found the two places the patch never reached.

Operator credential

▸ CVE-2026-53923 — the one I like most

A 32-bit integer truncation in vLLM's GGUF dequantization kernels. The kernel processes fewer elements than it allocated, so the tail of the output tensor is never written — it just keeps whatever was in GPU memory before.

On a multi-tenant inference server, that residue is another user's data.

Nothing crashes. No sanitizer fires. Every individual line of the kernel looks correct, and the types are all perfectly reasonable. It fails silently, which is exactly why it survived from 0.5.5 all the way to 0.23.1rc0.

CVSS 5.3 · CWE-681 + CWE-200 · GHSA-5jv2-g5wq-cmr4

Writeups: Medium · HackerNoon

◈ RANGE TIME — HACK THE BOX

Hack The Box live telemetry — AviralxRoot

◈ LIVE — htb-sync.yml re-reads the Hack The Box API every six hours and redraws this card whenever a number moves. Last change 2026-10-04 05:51 UTC.

AviralxRoot — Guru on points, Prodigy III · level 89 on XP. Global #65, 1,872 points, 72 user and 53 root flags, 254 challenges, 148 Sherlock tasks, and 6 fortresses cleared end to end. Nothing on this card is typed by hand.

▓ Independent Bug Reports — Disclosed Without CVE

Valid, reproducible findings where the vendor declined assignment (often behind a retroactive documentation shield). Published anyway.

Target Finding Severity Status
XGBoost ×5 Heap OOB in tree node access · UBJSON parser memory corruption · Parallel tree double-free · Unsafe pickle.loads() on network data (CWE-502) · Hardcoded 0xff99 magic as Rabit tracker auth (CWE-798) CRITICAL / HIGH Vendor declined — "performance + resourcing". Full writeup on Medium
Google sentencepiece Off-by-4 bounds check in DecodePrecompiledCharsMap → OOB read via crafted .model (UBSan-confirmed) MEDIUM Google VRP #498463886 — tokenizer backbone of Gemma, T5, PaLM
Google sentencepiece Unvalidated trie values used as piece-array indices → heap OOB read in release builds HIGH Google VRP #498465599 — upstream fix PR #1207
vLLM LoRA adapter SSRF → RCE chain HIGH Closed via documentation shield. Public writeup

Separate from the seven assigned CVEs above.

Capability Matrix

◈ STANDARDS BODY CONTRIBUTIONS

Body Contribution Detail
NIST OLIR Catalog Mapping — live First AI-security framework mapping in the NIST Online Informative References catalog: OWASP LLM Top 10 v2.0 → NIST CSF 2.0, with 169 relationship entries covering 77 of 106 CSF subcategories. Listed Point of Contact on the NIST CSRC website.
MITRE CWE / CAPEC submissions Weakness submissions in Phase-03 review, derived from CVE-2026-33017 (AI workflow definition injection).

◈ TRANSMISSIONS — INVITED TALKS

Full speaker profile → sessionize.com/aviral-srivastava

Year Conference Talk
2026 BSides Las Vegas Rejected-Input Programming: Exploiting Parsers That Say No Too Late — Breaking Ground, Aug 5
2026 RSAC 2026 From Prompt to Pager: Preparing for AI-Native Incidents Now
2026 ISACA North America Breaking the Loop: Offensive Testing of RL and Agentic AI Systems
2025 CactusCon 14 Agents Under Siege: Live Attacks from RAG to Tool Calls
2025 CypherCon 2025 Deceiving the Deceivers: Offensive Security Strategies for Adversarial AI
2025 BSidesSLC Filling Gaps in AI Governance: How ISO/IEC 42001 Shapes AI Risk & Compliance
2025 BSidesTC ROP Alchemy: Universal Gadgets via Type Confusion
2025 CactusCon 13 Weaponizing AI: Adversarial Attacks, Hallucinations, and the Offensive Frontier
2024 HOPE XV Invited talk — details under NDA
2024 BSidesChicago Hacking Neural Networks: The Hidden Vulnerabilities of AI Systems
▶ SIGNAL INTERCEPT — Press coverage of CVE-2026-33017

Quoted by name as the discoverer across major security press. This is the bug that went on to be nominated for a Pwnie.

◈ OPERATIONS — TOOLS & PIPELINES

▸ ZeroDayForge

Full-spectrum adversary emulation and exploit automation framework.

▸ Autonomous n-day Kernel Exploit Pipeline

Apple-silicon toolchain (radare2 · lldb · Ghidra headless) running RECON → AUTO-PICK → 12-POINT SAFETY GATE → PATCH ANALYSIS → ROOT CAUSE → EXPLOIT STRATEGY → COMPILE VERIFY, emitting Exploit-DB-format exploit.c.

▸ Multi-Agent CVE Hunting Pipeline

Agent team — Recon · Auditor · Exploiter · Reporter — governed by a 14-rule submission framework and a 4-gate filter (unauthenticated · default config · no doc shield · core feature).

▸ LLM-Driven Cryptographic CTF Generator

Automated cryptographic challenge generation. MS thesis, Penn State.

◈ DOSSIER

▸ Experience

Security Engineer (L4) — Amazon Ads Security Sunnyvale, CA · 2025 – Present

AppSec reviews · threat modeling · penetration testing · AI/ML security · agentic workflows · prompt injection · RAG hardening

Security Internships ×6 Malware RE · secure DevOps · GRC

Teaching Assistant — Red Teaming & CTFs The Pennsylvania State University

▸ Education

MS, Cybersecurity Analytics & Operations The Pennsylvania State University · GPA 4.0

Research Assistant · RSA Security Scholar Thesis: AI-Generated Cryptographic CTF Challenges

BTech, Computer Science — Amity University Cryptography · Secure Systems · Network Security

▸ Commendations




Hack The Box — AviralxRoot

The future belongs to offensive AI

Popular repositories Loading

  1. kernelghost kernelghost Public

    KernelGhost is a next-generation offensive security framework that combines stealthy eBPF-based rootkit capabilities with advanced hypervisor escape techniques. It enables persistent cross-VM acces…

    C 32 3

  2. AI-Attack-Mind-Map-Comprehensive-AI-Security-Threats-Attack-Vectors AI-Attack-Mind-Map-Comprehensive-AI-Security-Threats-Attack-Vectors Public

    The world’s most detailed AI Attack Mind Map covering LLMs, RAG, Agentic AI, RL, diffusion, MLOps, federated learning, and hardware side-channels.

    8 2

  3. AdversaryPilot AdversaryPilot Public

    ATLAS-aligned Bayesian attack planning & orchestration engine for LLM, agent, and ML systems

    Python 8 3

  4. Polymorphic-Shellcode-Engine Polymorphic-Shellcode-Engine Public

    A next-generation engine for generating metamorphic shellcode payloads with built-in evasion capabilities, designed for red team operations and penetration testing.

    Python 5

  5. vllm-integer-truncation-audit vllm-integer-truncation-audit Public

    Security audit documenting 221 silent int64-to-int32 truncation sites in vLLM's CUDA/C++ extensions that enable GPU buffer overflow via crafted GGUF model files.

    3

  6. awesome-ai-red-teaming awesome-ai-red-teaming Public

    Forked from shlomihod/awesome-ai-red-teaming

    A curated list of awesome AI Red Teaming resources and tools.

    2