0DAYSECADVISORY

Security Advisory Database

A collection of in-depth vulnerability advisories and security research reports published by Thomas A Hutomo, including technical writeups, CVE analyses, exploitation techniques, and remediation guidance.

Featured Advisory

CVE-2025-54314 High

Ruby on Rails Thor can construct an unsafe shell command from library input

Thor gem's file manipulation methods that allows attackers to execute arbitrary system commands through limited_dev unsafe shell command construction.

Ruby on Rails
Read Advisory

Recent Advisories

Security Research at 0daysec

Dedicated to discovering and documenting security vulnerabilities across various platforms and applications. Our research aids in creating more secure systems for everyone.

Vulnerability Discovery

Identifying new security vulnerabilities in software systems through systematic testing and analysis.

Responsible Disclosure

Following ethical security practices by reporting vulnerabilities to vendors before public disclosure.

Technical Documentation

Creating detailed reports with proof-of-concepts to help understand and address security issues.