Snir Aviv is an application security researcher at Cato Networks and member of Cato CTRL. Snir specializes in penetration testing, vulnerability research, and development of offensive security tools. Prior to joining Cato in 2024, Snir built and led the penetration testing team at Clear Gate, delivering high-impact security assessments for clients across diverse industries. Snir holds a Burp Suite Certified Practitioner (BSCP) certification, has published multiple CVEs, and is known for his practical approach to security challenges and his ability to uncover complex vulnerabilities.

Presentations

23x

Weaponizing Streamlit: Cloud Account Takeover Through File Upload Exploitation

File upload vulnerabilities in cloud-native apps are often underestimated, but a flaw in Streamlit’s st.file_uploader enabled attackers to bypass client-side checks, upload arbitrary files, and seize control of misconfigured cloud instances. This talk walks through the full exploit chain—from bypassing file filtering to gaining persistent access and manipulating live data pipelines—revealing how simple oversights can lead to market-scale risk and why trusting frontend logic is a dangerous mistake.

See Presentation