> cat ./research/race-against-the-patch-litellm.log
外部发表 STAR Labs ↗
Race Against The Patch: The Evolution of Four Exploit Chains in LiteLLM
围绕 Pwn2Own Berlin 2026,复盘 LiteLLM 四个版本中从低权限入口到容器 RCE 的四条利用链,以及补丁推进下不断重构攻击路径的过程。
$ ./swing --focus "vulnerability research"
# Know it then hack it!
VULNERABILITY RESEARCHER · CTF PLAYER
记录漏洞挖掘与分析、二进制安全、系统安全及 CTF 相关内容。
// ./LATEST_TRANSMISSIONS
> cat ./research/race-against-the-patch-litellm.log
外部发表 STAR Labs ↗
围绕 Pwn2Own Berlin 2026,复盘 LiteLLM 四个版本中从低权限入口到容器 RCE 的四条利用链,以及补丁推进下不断重构攻击路径的过程。
> cat ./research/CVE-2026-41651-analysis.log
> cat ./research/preempted-unlocking-xiaomi-via-two-unsanitized-strings.log
> cat ./research/pickling-the-mailbox-cve-2025-20393-cn.log
> cat ./research/how-to-patch-a-linux-kernel-bug-zh.log
> cat ./research/tp-link-wr841n-router-cve-analysis.log
> cat ./research/cve-2025-32023-redis-rce-via-out-of-bounds-write.log
> cat ./research/cve-2025-36463-sudo-chroot-elevation.log
> cat ./research/offbyone-conference-when-asus-iot-devices-play-hide-and-seek-with-security.log
> cat ./research/security-equipment-vulnerability-research.log