<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Developer Security on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/en-gb/tags/developer-security/</link>
    <description>Recent content in Developer Security on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-gb</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Sat, 18 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/en-gb/tags/developer-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>0day Hunting the Day After xAI Open-Sourced grok-build (Part 3): Grok-Build-CLI&#39;s folder-trust Blind Spot and the Zero-Prompt RCE</title>
      <link>https://blog.1sec.day/en-gb/posts/2026-07-18-grok-cli-folder-trust-bypass-rce/</link>
      <pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2026-07-18-grok-cli-folder-trust-bypass-rce/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>0day Hunting the Day After xAI Open-Sourced grok-build (Part 1): The cargo check RCE Chain in Grok-Build-CLI</title>
      <link>https://blog.1sec.day/en-gb/posts/2026-07-16-grok-cli-cargo-check-rce/</link>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2026-07-16-grok-cli-cargo-check-rce/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>0day Hunting the Day After xAI Open-Sourced grok-build (Part 2): The bypassPermissions RCE in Grok-Build-CLI and Claude Code CLI</title>
      <link>https://blog.1sec.day/en-gb/posts/2026-07-16-grok-build-cli-claude-code-bypass-permissions-rce/</link>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2026-07-16-grok-build-cli-claude-code-bypass-permissions-rce/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Grok CLI Whole-Repo Upload Reverse Analysis: How a Single Prompt Ships Your .env to the Cloud</title>
      <link>https://blog.1sec.day/en-gb/posts/2026-07-15-grok-cli-codebase-exfiltration/</link>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2026-07-15-grok-cli-codebase-exfiltration/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>CVE-2017-9841 PHPUnit eval-stdin.php Remote Code Execution: When a PHP Testing Framework Becomes a Web Entry Point</title>
      <link>https://blog.1sec.day/en-gb/posts/2017-05-15-cve-2017-9841-phpunit-rce/</link>
      <pubDate>Mon, 15 May 2017 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2017-05-15-cve-2017-9841-phpunit-rce/</guid>
      
      <description>&lt;p&gt;PHPUnit is one of the most popular unit testing frameworks in the PHP ecosystem, but its &lt;code&gt;eval-stdin.php&lt;/code&gt; file is designed as a tool to &amp;ldquo;accept PHP code via the CLI&amp;rdquo; — if this file is accidentally deployed to the production environment&amp;rsquo;s web directory, an attacker can execute arbitrary PHP code through a simple POST request, CVSS 9.8, no authentication required.&lt;/p&gt;</description>
      
    </item>
    
  </channel>
</rss>
