Vulnerability Log

Real vulnerabilities I find during pen tests, paired with the X post where I first shared them. The full writeup lives here.

Ryan O'Callaghan
Ryan O'Callaghan @ocallry Feb 2026

Exposed Admin API Route — No Auth Check

High
SaaS App Next.js Supabase OWASP A01

Don't end up in the log.

Get your app tested before someone else does.

See Pricing