aurora@hack:~$▌
~/main

~ / cases / rce

▣ Remote Code Execution

Deserialization, template injection, unsafe pipelines — getting a shell where there shouldn't be one.

[docker lab] unsafe-pipeline

Practice identifying and containing an unsafe document pipeline. Run it locally to practice the proof of concept in an isolated environment.

docker compose -f labs/rce up --build

aurora@hack:~$ ls ./cases/rce

▲ Critical9 min read

Trusted CSV Chat to Remote Pickle Deserialization

A trusted CSV-analysis workflow let an AI enrich a query with a remote model file, leading pandas to deserialize an attacker-controlled pickle and execute code.

#pandas#pickle#deserialization#ai-agent#ssrf
▲ Critical10 min read

Malicious Python Artifact Executed by an AI Sandbox

A hidden artifact-upload endpoint accepted a Python code artifact that the AI later executed with unrestricted builtins inside an isolated but overexposed sandbox.

#python#artifacts#sandbox#ai-agent#rce

other classes: arbitrary-file-read · prompt-injection-role-confusion · sqli · system-prompt-exfiltration

aurora-hack © 2026 — field notes from a red teamer

responsible disclosure only · no client data, no credentials, ever