Advisories

Security advisories from the vu1nz team.

PoC || GTFO. We publish what we find — CVE coordinates, disclosure timelines, and reproduction steps.

VU1NZ-2026-001·Jan 31, 2026

BeyondTrust Remote Support Pre-Auth RCE

Deserialization vulnerability in BeyondTrust Remote Support allowing unauthenticated remote code execution.

Critical
VU1NZ-2026-002·Feb 12, 2026

vLLM Auto Map RCE via Dynamic Module Loading

Untrusted dynamic module loading in vLLM allows arbitrary code execution through crafted model configurations.

High
VU1NZ-2026-003·Mar 5, 2026

React Router XSS via SSR ScrollRestoration

Cross-site scripting through the ScrollRestoration API in server-side rendered React Router applications.

Critical