Vulnerability research & coordinated disclosure

Peyton Kennedy.

Senior Security Researcher/p80n-sec

Peyton Kennedy

Peyton 'p80n-sec' Kennedy is a Senior Security Researcher at Endor Labs, where he focuses on offensive security research, vulnerability discovery, and exploit development against the open source projects shaping modern software. His research has produced CVE disclosures across widely deployed frameworks and platforms with a consistent focus on the gap between what platforms claim about their threat models and what they actually enforce.

01Published disclosures

CVE/GHSADateProjectCVSS Endor ReferenceBlog/ResourceTalk
2026-08-08DifyENDOR-VUL-2026-0105WriteupDEF CON 34
2026-08-08Kestra9.8ENDOR-VUL-2026-0202WriteupDEF CON 34
2026-08-08Kestra9.8ENDOR-VUL-2026-02021WriteupDEF CON 34
2026-08-08NocoBase9.9ENDOR-VUL-2026-16041WriteupDEF CON 34
2026-08-08NocoBase8.7ENDOR-VUL-2026-16044WriteupDEF CON 34
2026-08-08LangflowENDOR-VUL-2026-2601WriteupDEF CON 34
2026-08-08LangflowENDOR-VUL-2026-26012WriteupDEF CON 34
GHSA-j77w-g4jj-hp992026-08-07gh-aw9.6ENDOR-VUL-2026-0906
GHSA-9fpm-3445-2vx42026-08-04Langflow8.8ENDOR-VUL-2026-26011WriteupDEF CON 34
CVE-2026-734872026-07-29Flowise9.3ENDOR-VUL-2026-1704WriteupDEF CON 34
CVE-2026-730812026-07-17Activepieces8.7ENDOR-VUL-2026-30031WriteupDEF CON 34
CVE-2026-730832026-07-17Activepieces7.6ENDOR-VUL-2026-3003WriteupDEF CON 34
CVE-2026-554072026-07-01buffa6.3ENDOR-VUL-2026-2105Writeup
CVE-2026-416402026-04-22NocoBase7.5ENDOR-VUL-2026-16043WriteupDEF CON 34
CVE-2026-416412026-04-22NocoBase7.2ENDOR-VUL-2026-16042WriteupDEF CON 34
CVE-2026-308982026-04-17Apache Airflow8.8ENDOR-VUL-2026-0503WriteupDEF CON 34
CVE-2026-279592026-02-26Koa7.5ENDOR-VUL-2026-2301Writeup
CVE-2026-320602026-02-19OpenClaw8.7ENDOR-VUL-2026-04027Writeup
CVE-2026-263292026-02-18OpenClaw7.1ENDOR-VUL-2026-04026Writeup
CVE-2026-284762026-02-18OpenClaw6.3ENDOR-VUL-2026-04022Writeup
CVE-2026-296062026-02-18OpenClaw6.3ENDOR-VUL-2026-04024Writeup
CVE-2026-263192026-02-17OpenClaw7.5ENDOR-VUL-2026-04021Writeup
CVE-2026-263222026-02-17OpenClaw7.6ENDOR-VUL-2026-04025Writeup
GHSA-56f2-hvwg-57432026-02-17OpenClaw7.6ENDOR-VUL-2026-04023Writeup
CVE-2025-636622025-12-22GT Edge AI Platform7.5WriteupBSides NoVA 2025 · CackalackyCon 2026
CVE-2025-636632025-12-22GT Edge AI Platform7.5WriteupBSides NoVA 2025 · CackalackyCon 2026
CVE-2025-636642025-12-22GT Edge AI Platform7.5WriteupBSides NoVA 2025 · CackalackyCon 2026
CVE-2025-636652025-12-19GT Edge AI Platform9.8WriteupBSides NoVA 2025 · CackalackyCon 2026

CVSS scores are CISA-ADP assessments where NVD analysis is still pending.

02Pending disclosures

Reported and awaiting a fix, under a 90+30 day disclosure policy.

ReferenceProject / RepositoryDate ReportedDeadline Expires
None outstanding

03Talks

04Writing & tools