//
sign in
Post
by @danabra.mov
PostEmbed
by @danabra.mov
Record
by @jimpick.com
Record
by @atsui.org
+ new component
Post
Another bug I found in ProfileGrid was disclosed this week. Broken access control! cryptocat.me/blog/researc...
1mo
cryptocat.me
Root cause analysis of CVE-2026-4609 in ProfileGrid, where a nonce-only AJAX invite flow lets Subscriber-level users add themselves or other registered users to closed and paid groups.
ProfileGrid Missing Authorization Allows Subscriber+ Arbitrary Group Joining | CVE-2026-4609 | CryptoCat's Blog
CryptoCat