Vulnerability research & coordinated disclosure

Peyton Kennedy.

Senior Security Researcher/p80n-sec

Peyton Kennedy

Peyton 'p80n-sec' Kennedy is a Senior Security Researcher at Endor Labs, where he focuses on offensive security research, vulnerability discovery, and exploit development against the open source projects shaping modern software. His research has produced CVE disclosures across widely deployed frameworks and platforms with a consistent focus on the gap between what platforms claim about their threat models and what they actually enforce.

01Published disclosures

CVE/GHSADateProjectCVSS Endor ReferenceBlog/ResourceTalk
GHSA-p347-7m45-694r2026-09-08Huginn9.6ENDOR-VUL-2026-27082——
GHSA-p748-5grc-mcf52026-09-08Huginn7.3ENDOR-VUL-2026-27083——
GHSA-x738-j22q-h2jw2026-09-08Huginn8.1ENDOR-VUL-2026-2708——
GHSA-846c-fpfg-rj9m2026-08-29gh-aw9.6ENDOR-VUL-2026-0906——
—2026-08-08Dify—ENDOR-VUL-2026-0105WriteupDEF CON 34
—2026-08-08Kestra9.8ENDOR-VUL-2026-0202WriteupDEF CON 34
—2026-08-08Kestra9.8ENDOR-VUL-2026-02021WriteupDEF CON 34
—2026-08-08NocoBase9.9ENDOR-VUL-2026-16041WriteupDEF CON 34
—2026-08-08NocoBase8.7ENDOR-VUL-2026-16044WriteupDEF CON 34
—2026-08-08Langflow—ENDOR-VUL-2026-2601WriteupDEF CON 34
—2026-08-08Langflow—ENDOR-VUL-2026-26012WriteupDEF CON 34
GHSA-j77w-g4jj-hp992026-08-07gh-aw9.6ENDOR-VUL-2026-0906——
GHSA-9fpm-3445-2vx42026-08-04Langflow8.8ENDOR-VUL-2026-26011WriteupDEF CON 34
CVE-2026-734872026-07-29Flowise9.3ENDOR-VUL-2026-1704WriteupDEF CON 34
CVE-2026-730812026-07-17Activepieces8.7ENDOR-VUL-2026-30031WriteupDEF CON 34
CVE-2026-730832026-07-17Activepieces7.6ENDOR-VUL-2026-3003WriteupDEF CON 34
CVE-2026-554072026-07-01buffa6.3ENDOR-VUL-2026-2105Writeup—
CVE-2026-416402026-04-22NocoBase7.5ENDOR-VUL-2026-16043WriteupDEF CON 34
CVE-2026-416412026-04-22NocoBase7.2ENDOR-VUL-2026-16042WriteupDEF CON 34
CVE-2026-308982026-04-17Apache Airflow8.8ENDOR-VUL-2026-0503WriteupDEF CON 34
CVE-2026-279592026-02-26Koa7.5ENDOR-VUL-2026-2301Writeup—
CVE-2026-320602026-02-19OpenClaw8.7ENDOR-VUL-2026-04027Writeup—
CVE-2026-263292026-02-18OpenClaw7.1ENDOR-VUL-2026-04026Writeup—
CVE-2026-284762026-02-18OpenClaw6.3ENDOR-VUL-2026-04022Writeup—
CVE-2026-296062026-02-18OpenClaw6.3ENDOR-VUL-2026-04024Writeup—
CVE-2026-263192026-02-17OpenClaw7.5ENDOR-VUL-2026-04021Writeup—
CVE-2026-263222026-02-17OpenClaw7.6ENDOR-VUL-2026-04025Writeup—
GHSA-56f2-hvwg-57432026-02-17OpenClaw7.6ENDOR-VUL-2026-04023Writeup—
CVE-2025-636622025-12-22GT Edge AI Platform7.5—WriteupBSides NoVA 2025 · CackalackyCon 2026
CVE-2025-636632025-12-22GT Edge AI Platform7.5—WriteupBSides NoVA 2025 · CackalackyCon 2026
CVE-2025-636642025-12-22GT Edge AI Platform7.5—WriteupBSides NoVA 2025 · CackalackyCon 2026
CVE-2025-636652025-12-19GT Edge AI Platform9.8—WriteupBSides NoVA 2025 · CackalackyCon 2026

CVSS scores are CISA-ADP assessments where NVD analysis is still pending.

02Pending disclosures

Reported and awaiting a fix, under a 90+30 day disclosure policy.

ReferenceProject / RepositoryDate ReportedDeadline Expires
None outstanding

03Talks

04Writing & tools