Skip to content

Latest research: Read the advisory

Research and writing from the people who find the bugs.

Deep-dive vulnerability analyses, weaponized proofs-of-concept, and security research, written by the Starfish founders. Grounded in the public record; sources credited.

4
published write-ups
4
CVEs dissected
3
founding researchers
Author
Topic

4 posts

Phuoc Pham9 min

Sitecore CVE-2025-53690: a sample machine key from the docs, turned into unauthenticated RCE

A machine key copied verbatim out of Sitecore's own 2017 deployment guide lets an attacker forge a valid ASP.NET ViewState and reach pre-auth RCE. This is a full walkthrough: from the leaked key, to a ysoserial.net payload that lands, to a fileless in-memory route handler that survives the patch.

CVE-2025-53690 9.0CVE AnalysisDeserializationReverse EngineeringRead