[CVE-2026-22588] Tales From the Trace: How XBOW Reasons Its Way Into Finding IDORs
xbow.com | blog | CVE-2026-22588 | #agentic-ai | #appsec | #vulnerability-research | #idor | #cve | #ai-pentesting | #authorization | #spree
Summary
Walks through XBOW traces that found two IDORs in the Spree e-commerce framework (CVE-2026-22588/22589, patched in v5.2.5) by reasoning about objects and authorization states.
- Published
- Collected
Skip to content