Skip to content
Research

Selected research & disclosures

A curated view of the work. Some entries are anonymized or summarized where programs require confidentiality; full write-ups are linked where public.

WebCritical

IDOR chain leading to full account takeover

A predictable object reference combined with a weak authorization check allowed cross-tenant access and a complete takeover path.

Fixed · 2026
CloudCritical

SSRF reaching cloud instance metadata

A server-side request forgery primitive in an import feature reached the metadata endpoint, exposing scoped credentials.

Coordinated · 2026
APIHigh

Authorization bypass in a GraphQL resolver

A nested resolver skipped an ownership check, allowing authenticated users to read records outside their organization.

Fixed · 2025
WebHigh

OAuth token theft via open redirect

A loosely validated redirect parameter in the authorization flow enabled exfiltration of access tokens to an attacker origin.

Disclosed · 2025
CloudHigh

Public bucket exposing build artifacts and secrets

A misconfigured storage bucket exposed CI artifacts, revealing a long-lived credential that widened the blast radius.

Fixed · 2025
InfrastructureMedium

Subdomain takeover via dangling CNAME

A dangling DNS record pointing to a deprovisioned service allowed content control on a trusted subdomain.

Fixed · 2024
ToolingMedium

Continuous attack-surface monitoring suite

An internal automation pipeline for asset discovery, change detection, and prioritized alerting across large scopes.

Disclosed · 2024
MobileMedium

Certificate-pinning bypass enabling traffic inspection

A weakness in the pinning implementation permitted interception of API traffic under a controlled test environment.

Coordinated · 2024

Have a program, a target, or a hard problem?

Whether you run a bug bounty program or need focused security research, Senvia can help. Reach out and let's talk scope.