
Capivara
Aug 28, 2026
The green padlock that couldn't see the leak — path traversal in Capivara
Gitleaks, bandit and opengrep ran weekly and everything stayed green. Even so, a single GET request returned the entire .env in production. The hole wasn't a committed secret — it was a path my own code opened. And the one who found it wasn't the scanner.
Continue reading →