<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #rce</title><description>Articles tagged rce on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>An AI agent found 21 ways to attack FFmpeg, the codec library inside almost everything</title><link>https://devtake.dev/article/ffmpeg-21-zero-days/</link><guid isPermaLink="true">https://devtake.dev/article/ffmpeg-21-zero-days/</guid><description>DepthFirst&apos;s agent surfaced 21 FFmpeg zero-days for about $1,000. One 183-byte packet hits RCE. The deeper story is who pays the volunteers who fix them.</description><pubDate>Sat, 13 Jun 2026 13:00:00 GMT</pubDate><category>security</category><category>security</category><category>ffmpeg</category><category>open-source</category><category>rce</category><category>vulnerability</category><category>fuzzing</category><author>luca-reinhardt</author></item><item><title>VS Code&apos;s webview sandbox leaks GitHub tokens that read and write every private repo</title><link>https://devtake.dev/article/vscode-zero-day-github-token-theft/</link><guid isPermaLink="true">https://devtake.dev/article/vscode-zero-day-github-token-theft/</guid><description>A disclosed VS Code zero-day lets one click on a malicious github.dev notebook steal a GitHub OAuth token with full read-write access to every private repo.</description><pubDate>Wed, 03 Jun 2026 13:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>credential-theft</category><category>dev-tools</category><category>rce</category><category>supply-chain</category><category>oauth</category><author>luca-reinhardt</author></item><item><title>GitHub banned the researcher dropping Windows zero-days. The code was already mirrored everywhere.</title><link>https://devtake.dev/article/github-bans-researcher-windows-zero-day/</link><guid isPermaLink="true">https://devtake.dev/article/github-bans-researcher-windows-zero-day/</guid><description>GitHub wiped Nightmare-Eclipse&apos;s account on May 23 after weeks of unpatched Windows exploits. The ban reopened the oldest fight in security: who decides what research gets hosted?</description><pubDate>Fri, 29 May 2026 06:50:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vulnerability-disclosure</category><category>zero-day</category><category>microsoft</category><category>windows</category><category>supply-chain</category><category>rce</category><author>luca-reinhardt</author></item><item><title>A bad command-line parser turned every claude-cli:// link into a remote shell</title><link>https://devtake.dev/article/claude-code-rce-deeplink-cve/</link><guid isPermaLink="true">https://devtake.dev/article/claude-code-rce-deeplink-cve/</guid><description>Joernchen of 0day.click found a deeplink RCE in Claude Code. Anthropic shipped the fix in 2.1.118 the same week.</description><pubDate>Wed, 20 May 2026 09:15:00 GMT</pubDate><category>security</category><category>security</category><category>anthropic</category><category>claude-code</category><category>rce</category><category>ai-security</category><category>supply-chain</category><category>ai-agents</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>F5 patched an 18-year-old NGINX bug. Attackers can RCE a third of the web with one crafted request.</title><link>https://devtake.dev/article/nginx-rift-18-year-rce/</link><guid isPermaLink="true">https://devtake.dev/article/nginx-rift-18-year-rce/</guid><description>F5 disclosed CVE-2026-42945 on May 13 after depthfirst&apos;s analyzer found a heap overflow in a 2008 commit. NGINX 1.31.0 ships the patch, every Plus tier needs an upgrade.</description><pubDate>Thu, 14 May 2026 10:30:00 GMT</pubDate><category>security</category><category>security</category><category>nginx</category><category>f5</category><category>cve-2026-42945</category><category>rce</category><category>heap-overflow</category><category>depthfirst</category><category>ai-security</category><author>luca-reinhardt</author></item><item><title>Wiz found an RCE in GitHub&apos;s git-push pipeline. The patch shipped in six hours.</title><link>https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</link><guid isPermaLink="true">https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</guid><description>CVE-2026-3854 is a CVSS 8.7 RCE in GitHub&apos;s git-push pipeline. github.com fixed it within hours. 88% of Enterprise Server installs were still vulnerable at disclosure.</description><pubDate>Wed, 29 Apr 2026 09:05:00 GMT</pubDate><category>security</category><category>github</category><category>security</category><category>cve-2026-3854</category><category>rce</category><category>supply-chain</category><category>wiz</category><category>github-actions</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>A malicious GGUF file owns your SGLang server: CVE-2026-5760 is an unpatched 9.8</title><link>https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</link><guid isPermaLink="true">https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</guid><description>SGLang&apos;s reranker renders chat templates without a sandbox. Load a hostile GGUF, hit /v1/rerank, and the attacker has Python on your inference box. No patch yet.</description><pubDate>Mon, 27 Apr 2026 11:30:00 GMT</pubDate><category>security</category><category>sglang</category><category>cve-2026-5760</category><category>supply-chain</category><category>ai-security</category><category>llm</category><category>rce</category><category>jinja2</category><category>gguf</category><author>luca-reinhardt</author></item><item><title>protobuf.js RCE: a 52M/week npm package was one bad type name from code execution</title><link>https://devtake.dev/article/protobuf-javascript-rce-cve/</link><guid isPermaLink="true">https://devtake.dev/article/protobuf-javascript-rce-cve/</guid><description>GHSA-xq3m-2v4x-88gg hits protobuf.js ≤8.0.0 / ≤7.5.4. Attacker-controlled schemas executed arbitrary JS on decode. One-line fix patched it.</description><pubDate>Tue, 21 Apr 2026 12:00:00 GMT</pubDate><category>security</category><category>npm</category><category>protobuf</category><category>javascript</category><category>supply-chain</category><category>rce</category><category>endor-labs</category><category>grpc</category><author>luca-reinhardt</author></item></channel></rss>