GRIMPIT LABS Case files
Grimpit, a hooded skeleton wearing glowing orange goggles

The Grimpit Dispatch

Bad code
dies here.

Real security flaws, dissected. New case files, tools, and experiments from the crypt, delivered to your inbox.

No algorithm. No feed. Just bad code being properly reaped.

What rises from the crypt

01

Case files

Real vulnerabilities, broken down: how they worked, why they got missed, and how to fix them.

02

Tools & experiments

Scripts, labs, and tools from the Grimpit workshop, shared here before they show up anywhere else.

03

No filler

No roundups. No link dumps. Every dispatch is something you can actually use.

Case File 001 slide: Supabase RLS looked fine. Users could only update their own profile row.

Case File #001

One Column, Full Admin

A Supabase Row-Level Security policy correctly limited users to updating their own profile row.

It just forgot something rather important: which columns they could update.

PATCH /rest/v1/profiles?id=eq.<uuid>

{
  "display_name": "alex",
  "role": "admin"
}

The UI hid the field. The API accepted it anyway.

Read the full case file →
Grimpit seated in a gothic cathedral filled with monitors and candles

Who writes this

Grimpit, The Reaper of Bad Code

Grimpit is the Reaper of Bad Code — a cybersecurity character focused on pentesting, AppSec, security research, tools, bugs, breaches, and the bad assumptions that make all of the above possible. Expect case files, technical breakdowns, experiments, security lessons, and the occasional autopsy of a decision that probably should not have made it to production.

From the crypt

Get the next case file before it goes anywhere else.