This website requires JavaScript.
Explore
Help
Register
Sign In
azcomputerguru
/
guru-connect
Watch
1
Star
0
Fork
0
You've already forked guru-connect
Code
Issues
18
Pull Requests
Actions
Packages
Projects
Releases
2
Wiki
Activity
Labels
Milestones
New Issue
5 Open
0 Closed
Label
Show archived labels
Use
alt
+
click/enter
to exclude labels
All labels
No label
component:agent
component:dashboard
component:server
security
severity:critical
severity:high
Milestone
All milestones
No milestones
Project
All projects
No project
Author
All users
Assignee
Assigned to nobody
Assigned to anybody
azcomputerguru
Sort
Newest
Oldest
Most recently updated
Least recently updated
Most commented
Least commented
Nearest due date
Farthest due date
Label
5 Open
0 Closed
Close
Label
Clear labels
component:agent
component:dashboard
component:server
security
severity:critical
severity:high
Milestone
No milestone
Projects
Clear projects
Assignee
Clear assignees
No assignee
azcomputerguru
[C5] Auto-update verified only by SHA-256 over same channel, no signature -> fleet-wide SYSTEM RCE on MITM
component:agent
security
severity:critical
#14
opened
2026-06-05 17:35:20 -07:00
by
azcomputerguru
[C4] Agent block_in_place/Handle::block_on in main async session loop -> thread-starvation/deadlock
component:agent
security
severity:critical
#13
opened
2026-06-05 17:35:11 -07:00
by
azcomputerguru
[C3] downloads.rs body().unwrap() on attacker-controlled Content-Disposition filename -> unauthenticated panic/DoS
component:server
security
severity:critical
#12
opened
2026-06-05 17:35:05 -07:00
by
azcomputerguru
[C2] Unauthenticated downloads.rs: hardcoded prod relay URL + default API-key fallback + false support-embedding docstring
component:server
security
severity:critical
#11
opened
2026-06-05 17:35:00 -07:00
by
azcomputerguru
[C1] Secrets/tokens in WebSocket URL query strings
component:agent
component:dashboard
security
severity:critical
#10
opened
2026-06-05 17:34:55 -07:00
by
azcomputerguru