Critical vulnerabilities found in conference review system HotCRP
moyix · x · 2026-08-19
Nebula Security found CVE-2026-55493 in HotCRP, a 9-year-old vulnerability that could expose reviewer identities. At minimum, it reveals who accepted or rejected papers. Another vulnerability, CVE-2026-63491, was also found. Both were responsibly disclosed to Eddie Kohler, who quickly fixed them. HotCRP is a widely used system for academic conference reviewing.
More from Safety
- Korea's $400M sovereign AI model pick sparks backlash as top scorer Motif is eliminated — teortaxesTex · 2026-08-19
- GPT-5.6 Risk Recapped: Codex Fixed Destructive Actions Deleting User Files — SIGKITTEN · 2026-08-19
- Paper: Silly Rules Help AI Understand Human Normative Systems — ghadfield · 2026-08-19
- Opinion: AI Safety Regulation Should Involve Legal Penalties — mayfer · 2026-08-19
- AI Sandbox Escapes Are Not Selling Points for Enterprise CIOs and Security — Miles_Brundage · 2026-08-19
- xAI Updates Grok 4.6 Model Card, Revises Evaluations — Miles_Brundage · 2026-08-19