blog

Notes from the field

Vulnerability write-ups and research from the RadvanSec team.

5 min read Oct 09, 2026

From a Forgotten XSS to Full Account Takeover: A Chain Inside OAuth

A reflected XSS on a subdomain trusted by the OAuth flow couldn’t directly read an id_token sent inside a protected POST body, so a redirect_uri parsing quirk was used to push the token into the URL instead, resulting in full account takeover.

nexovir
read >
5 min read Oct 05, 2026

One-Click Full Account Takeover via Chained XSS: Bypassing CSP by Pivoting Through a Trusted Subdomain

A reflected XSS on the main domain couldn't exfiltrate data past a strict CSP, so it was chained with a second XSS on a trusted subdomain to bypass it entirely, resulting in full account takeover.

nexovir
read >