Hii, I’m Nishant!

Just Another Homo Sapien interested in how things work and trying my best to break them!

From XSS to MCP Takeover: Hacking Cloudflare's AI Playground

Third post about Cloudflare in a row – I promise I hack other things too. This one is about a Reflected XSS I found in Cloudflare’s AI Playground that could steal any user’s chat history and interact with their connected MCP Servers. Along the way, I had to bypass Cloudflare’s own WAF, upgrade from a 2-click exploit to a single-click one, and watch the fix get patched twice before it actually stuck....

February 14, 2026 · 6 min · Nishant

When You Get Your MCP Wrong: Second-Order XSS to Cloudflare Access Account Takeover

Writing something after such a long time. While I wrote the last post with some desperation, I really wanted to elaborate on something interesting I discovered, in some clean fashion. I submitted a couple of nice escalations to Cloudflare in the past couple of months and this one talks about one of them. One fine evening after finishing work at daytime, I noticed Kenny’s post about Cloudflare’s new MCP Server Portal feature....

December 16, 2025 · 8 min · Nishant

Almost Hacking into Cloudflare's CEO

In the past few months, there have been multiple public disclosures related to SAML Bypasses. This writeup is loosely inspired from them and my journey to uncover yet another SAML Bypass! If you aren’t familiar with SAML already, I’ll recommend to read the ProjectDiscovery blog first. Preparation It was a regular day when I encountered a public disclosure post about SAML Signature bypass in Github Enterprise. It was a Critical Severity vulnerability....

January 8, 2025 · 7 min · Nishant