Sylvie
@_sy1vi3
Followers
836
Following
2K
Media
52
Statuses
993
AhRZbVYwWVM1emVXeDJhV1V1Wm5scAoccUtabXB6NXVvSkg2TElPMXAzTWFuMU4ycGo9PQ==
she/her 20
Joined May 2021
this is almost a relief i can't lie, i've lost so much sleep this past week going for these
2
2
49
my teammates gonna make me take a break from playing vercelctf this weekend to play seccon instead and i think thats kinda messed up honestly
1
0
17
can a girl get one teensy little prototype pollution gadget as a treat or is that too much to ask for
2
1
32
in trying to break vercel's firewall ive discovered a whole bunch of things that seem like Problems™ in their own right that make me somewhat hesitant to trust the security anything else going on here
1
0
40
y'all're gonna be disappointed when next week rolls around and i go back to never saying anything other than the occasional reply to a friend's tweet
0
0
16
another silly takeaway i got from all of this is that despite not being a frontend dev and generally being a proponent of just coping with raw html/js, ive learned that NextJS is actually pretty fun and easy to work with all things considered
2
1
37
vercel's WAF seems very effective at one thing at least, and that's keeping me up until 6am
5
0
72
i think one of the funniest outcomes of this whole thing is that ive developed something of a sixth sense for knowing if something is a NextJS/Vercel app before even checking devtools
0
0
29
i interacted with too many security slop posters and now my timeline is full of bug bounty skids instead of silly gay people this is so heartbreaking đź’”
5
1
63
This is streamingly exciting https://t.co/hD3e8tDTgb
github.com
Original Proof-of-Concepts for React2Shell CVE-2025-55182 - lachlan2k/React2Shell-CVE-2025-55182-original-poc
2
24
105
to be clear, this bug belongs to Lachlan, and for the time being the level of credit currently given to me on https://t.co/AgbXeD3ujX is roughly accurate. we both plan to make detailed blog posts about this at some point in the future.
1
0
22
while Lachlan began working with Meta and Vercel to get it patched, i began doing reconnaissance to identify vulnerable websites so that we could alert everyone who needed to be alerted immediately after the initial advisory went out.
1
1
12
i feel i should mention that the initial full RCE PoC had 20+ gadgets, while the one Lachlan submitted to Meta and the ones floating around the internet right now only have like 3.
1
0
10
we realized the significance of this immediately, and after discussing it we agreed that the bug was his and the PoC was his. Lachlan spent well over 100 hours working on this, to my ~36.
1
0
11