# Vulnerability research and advisories

Actionable writeups with exploit context, metadata, and practical remediation details.

[**Template injection vector in CI pipeline variables**  
Analysis of a templating flaw that allows untrusted input to alter build-time commands.  
Feb 10, 2026 • high  
CWE-94 CVE-2026-10001](/content/research/cve-template-injection-ci/index.html)  
[**Container registry token exposure through verbose logs**  
Leaked registry credentials observed in debug-level CI logs and artifact bundles.  
Jan 26, 2026 • medium  
CWE-532](/content/research/container-registry-token-exposure/index.html)  
[**Infrastructure policy bypass via nested module inheritance**  
A misconfiguration pattern in IaC modules can bypass deny rules under specific nesting conditions.  
Dec 5, 2025 • critical  
CWE-284 CVE-2025-23088](/content/research/infrastructure-policy-bypass/index.html)

No matching content found.
