<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Marcel Karlsson</title><link>https://decentsecurity.io/</link><description>Recent content on Marcel Karlsson</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 23 Sep 2026 02:41:28 +0000</lastBuildDate><atom:link href="https://decentsecurity.io/index.xml" rel="self" type="application/rss+xml"/><item><title>Stealing Financial Data on Logout: A DOM XSS Story</title><link>https://decentsecurity.io/posts/stealing-financial-data-on-logout-dom-xss/</link><pubDate>Wed, 23 Sep 2026 02:41:28 +0000</pubDate><guid>https://decentsecurity.io/posts/stealing-financial-data-on-logout-dom-xss/</guid><description>A logout redirect validated the hostname and ignored the scheme. One encoded newline turned it into same-origin DOM XSS that waited for login and read loan and bank data.</description></item><item><title>Escaping VS Code Webviews: The return of the path traversal</title><link>https://decentsecurity.io/posts/escaping-vs-code-webviews-the-return-of-the-path-traversal/</link><pubDate>Wed, 23 Sep 2026 02:20:37 +0000</pubDate><guid>https://decentsecurity.io/posts/escaping-vs-code-webviews-the-return-of-the-path-traversal/</guid><description>How an encoded slash bypassed VS Code&amp;rsquo;s Webview resource allowlist and turned a sandboxed view into an arbitrary file reader.</description></item><item><title>How to Freeze a Blockchain with 320 Valid Blocks</title><link>https://decentsecurity.io/posts/how-to-freeze-a-blockchain-with-320-valid-blocks/</link><pubDate>Wed, 23 Sep 2026 02:13:01 +0000</pubDate><guid>https://decentsecurity.io/posts/how-to-freeze-a-blockchain-with-320-valid-blocks/</guid><description>How misplaced rate limits let one validator freeze a blockchain with 320 valid blocks and no transaction fees.</description></item><item><title>How a grocery app's photo upload became a one-tap account takeover</title><link>https://decentsecurity.io/posts/image-upload-to-account-takeover/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://decentsecurity.io/posts/image-upload-to-account-takeover/</guid><description>I tried to hide code in a picture. A few dead-ends later, one ordinary HTTPS link ran my JavaScript inside any user&amp;rsquo;s logged-in app. No password, one tap.</description></item><item><title>CVE's</title><link>https://decentsecurity.io/cves/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://decentsecurity.io/cves/</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-47284"&gt;Microsoft: CVE-2026-47284&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-81383"&gt;Microsoft: CVE-2026-81383&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://aws.amazon.com/security/security-bulletins/2026-099-aws/"&gt;Amazon AWS: CVE-2026-85781&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>