BSides Toronto 2025

Snir Aviv

Snir Aviv is an application security researcher at Cato Networks and member of Cato CTRL. Snir specializes in penetration testing, vulnerability research, and development of offensive security tools. Prior to joining Cato in 2024, Snir built and led the penetration testing team at Clear Gate, delivering high-impact security assessments for clients across diverse industries. Snir holds a Burp Suite Certified Practitioner (BSCP) certification, has published multiple CVEs, and is known for his practical approach to security challenges and his ability to uncover complex vulnerabilities.


Session

10-05
11:00
25min
Weaponizing Streamlit: Cloud Account Takeover Through File Upload Exploitation
Snir Aviv, Yuval Moravchick

File upload vulnerabilities in cloud-native environments can have catastrophic consequences far beyond their perceived low severity. This session exposes a major flaw in Streamlit’s st.file_uploader widget, demonstrating a real-world exploit chain from bypassing client-side checks to gaining persistent access, manipulating cloud roles, and tampering with live data dashboards. Learn why trusting frontend logic is dangerous and how open-source misconfigurations become high-impact attack surfaces.

ENG 103