<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — deserialization</title><link>https://exploit-intel.com/blog/tags/deserialization/</link><description>EIP research articles tagged deserialization.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/deserialization/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Sun, 29 Mar 2026 00:00:00 -0400</lastBuildDate><item><title>WP Google Map Plugin - Three Weak Links, One Critical Chain</title><link>https://exploit-intel.com/blog/posts/wp-google-map-plugin/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/wp-google-map-plugin/</guid><description>Line 781 says $query_to_run is safe. It isn't. An autonomous pipeline found a CVSS 9.8 unauthenticated SQL injection in WP Google Map Plugin v4.9.1 -- a three-link chain of individually harmless components that, together, give any visitor full database access. Then we kept reading and found the plugin deserializes update-check responses from an external server with maybe_unserialize(). 200,000+ active installs. 35 minutes. $8.97.</description><pubDate>Sun, 29 Mar 2026 00:00:00 -0400</pubDate></item><item><title>CVE-2025-26866: From Undocumented Binary Protocol to Root Shell - AI Agent Meets Java Deserialization</title><link>https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</guid><description>CVE-2025-26866 is a Hessian deserialization RCE in Apache HugeGraph PD. Our autonomous exploit pipeline CVEForge - which had completed 56 consecutive CVEs - hit a wall: an undocumented binary protocol, a non-standard serialization format, and a class blacklist blocking every known gadget chain. The agent spent $49 and four hours reverse-engineering SOFABolt, mapping sofa-hessian byte by byte, and finding a JDK-only gadget chain to bypass the blacklist. Then we took over to turn file creation into a proper root shell - navigating JNDI hardening, CC library defenses, and a gadget chain that silently dies on modern JDK. The result: a full Metasploit module.</description><pubDate>Sun, 01 Mar 2026 18:00:00 -0400</pubDate></item><item><title>Zero to RCE: Autonomous Exploit Development Across Three Vulnerability Classes</title><link>https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</guid><description>After CVEForge's first successful run, we needed to know if it was luck or a pattern. Two more CVEs, zero hand-holding, and an AI agent that found a fix bypass the developers missed.</description><pubDate>Thu, 26 Feb 2026 12:00:00 -0400</pubDate></item></channel></rss>
