Skip to main content
Elliot Belt

Elliot Belt

Student & Offensive Security Researcher

Welcome
#

Hi! I’m Felix Billières, also known as Elliot Belt.

Learn more about me →

Recent

MCP SVG Icon Injection: From XSS to RCE Through the Protocol Spec

MCP SVG Icon Injection: From XSS to RCE Through the Protocol Spec

A deep dive into a protocol-level vulnerability in the Model Context Protocol (MCP) specification where malicious SVG icons delivered via data: URIs can escalate from XSS to full RCE on Electron clients. Reported to Anthropic VDP, closed as Informative — disclosed here with full technical details.