Romain Deperne
9 exploits
Active since Mar 2026
JupyterHub: Cross-origin form POSTs bypass XSRF
CVSS 5.4
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
CVSS 8.3
KubeAI <0.23.2 Ollama Model URL - OS Command Injection
CVSS 8.7
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
CVSS 8.6
MCP Atlassian <0.17.0 - Path Traversal
CVSS 9.0
Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
CVSS 7.2
graphiti-core < 0.28.2 - Cypher Injection via SearchFilters.node_labels
CVSS 8.1
Azure Data Explorer MCP Server <=0.1.1 - KQL Injection
CVSS 8.3
Plunk <0.8.0 Raw MIME Construction - Email Header Injection
CVSS 8.5