This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Hexmortem Labs
hexmortem.com
did:plc:ob77vazfvnsjq74uuutvgzz3
CVE-2026-41492 — Dgraph admin token leak.
The prior CVE was fixed by blocking /debug/pprof/cmdline. expvar auto-registers /debug/vars on the same default mux. cmdline leaks there too — three unauth GETs yield the token, one replay = admin.
v25.3.3 filters cmdline out. Patch.
2026-05-06T09:46:55.673Z