Disclosures
Security findings reported responsibly to the affected projects, several surfaced by the Arbiter and Aletheia tooling. Where a CVE has been assigned, it is noted.
Anthropic: open-source MCP tooling
Disclosed & acknowledgedVulnerability discovered in Anthropic's open-source MCP tooling and reported via Anthropic's security disclosure programme. Surfaced with Arbiter and Aletheia.
Cloudflare: Pingora
DisclosedA security issue identified in Cloudflare's Pingora open-source HTTP infrastructure. Surfaced with Arbiter.
SecureDrop: journalist API session replay
CVE-2026-50000 · fixed in 2.16.0The Flask session interface did not isolate API sessions from web sessions, so a journalist API token could be replayed against the Journalist Interface web UI until it expired (CVSS 5.0). Reported to the project and credited as a reporter in the advisory (GHSA-78xq-8jf3-gpfx); fixed in SecureDrop 2.16.0. The finding informed the design of Veilguard, a clean-room Rust rebuild.
Log4Shell: incident response (2021)
For the recordNot a discovery, but worth recording: I led the Log4Shell incident response at Kobalt Music, and founded the Security Incident Response Team there. Documented for completeness rather than as a formal vulnerability disclosure.
Coordinated disclosure enquiries: laurence@arbitersec.com. A machine-readable policy is published at /.well-known/security.txt.