DCODX.AI

Whitebox pentesting using skilled AI agents powered by GraphRAG representation of attack paths

Securing Open Source

OUR findings

HIGH

CVE-2026-22033

HumanSignal/label-studio

Full account takeover chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

MEDIUM

GHSA-hvq7-hq9r-8gjr

immich-app/immich

Shared-link authentication allows adding owner’s assets to shared links 

MEDIUM

CVE-2026-27397

really-simple-ssl-pro

Really Simple Security Pro <= 9.5.4.0 – Authenticated (Subscriber+) Insecure Direct Object Reference