Pentesting, AI security, red team operations — what we learn breaking systems so you don’t have to.
How we gained a reverse shell on LocalAI 2.17.1 by abusing the model file upload feature to overwrite a backend binary.
How we gained a reverse shell on Langflow 1.0.12 by abusing the unsandboxed custom component execution endpoint.
How we gained a reverse shell on InvokeAI 5.3.0 by serving a malicious pickle payload through the unauthenticated model install endpoint.