Learn/Write-up
Write-upSQL / command injection

RCE in image-processing worker

How a critical sql / command injection in secure.meridianbank.com was found, reported to Meridian Bank and fixed.

r0@r00tcauseAug 2026 · 4 min read
Verified findingCriticalReported to Meridian Bank · resolved 1 month ago

Summary

A critical issue in secure.meridianbank.com, reported to Meridian Bank and now fixed. This is the story of finding it, what it would have cost, and what changed.

Finding it

The interesting part was not the bug itself but the assumption behind it: that a value checked once stays checked. It does not.

http
POST /api/v2/refresh HTTP/1.1 Host: meridianbank.com Content-Type: application/json {"token":"<redacted>"}

Impact

An attacker could exploit this against Meridian Bank production traffic without prior access.

What changed

Meridian Bank shipped a fix and confirmed it on retest. Worth reading their scope before you start — it is unusually specific about what counts.

← More from Learn

More from @r00tcause