§ Proof

Three independent surfaces.

SecHive's public proof is split: a redacted bug bounty corpus showing real-world breadth, full-fidelity Juice Shop reports for reproducibility, and a controlled XBOW-style benchmark campaign in between.

  1. CS.01Runtime authorization replayA signed one-time action that executes more than once. The proof shape is what makes it credible.CVSS High/Critical
  2. CS.02Validation boundary / denylist bypassA policy enforced on one route, skipped on another. Outbound checked, inbound released.Critical impact
  3. CS.03Cross-domain / cross-asset logic abuseAn authorization for object A, rebound to object B through hook or forwarding data.Critical impact
  4. CS.04XBOW-style benchmark campaign104 cases, 99 black-box wins, 104 white-box wins.benchmark
  5. CS.05Bug bounty proof pack90 sanitized results across six method families, HackerOne-shaped.external
  6. CS.06CVE-2026-64606 — Apache Fory SerializedLambda registration bypassStrict class registration held for an ordinary class and admitted the equivalent interface. Fixed in 1.4.0.9.8 Critical
  7. CS.07CVE-2026-16534 — Import and Export Users and Customers privilege escalationA CSV import path skipped the role-assignment and per-user edit checks wp-admin enforces. Fixed in 2.4.2.7.2 High
  8. CS.08CVE-2026-15054 — Bit Form unauthenticated inactive-form submissionThe active-form check gated rendering but not processing. Fixed in 3.1.2.3.7 Low
  9. CS.09Juice Shop reference reportFull unredacted reproducible benchmark report.benchmark