Technical

A privilege escalation vulnerability hid behind a broken endpoint and a misleading error message. Here's how RAID's agentic system decompiled the frontend JavaScript to find the real API path, the real field name, and a critical access control flaw that let a standard user grant themselves admin rights.