/ˈbar/ • nouns
Security Researcher and CTF Player with @Try4gain. Mostly into reverse engineering, forensics, web exploitation, and linux.
Besides security shit, I enjoy playing a pixel art games and watching anime.
cve-2026-49355 exposed private work package data through the single meeting agenda item api in openproject
cve-2026-50198 and cve-2026-50199 in wallos were both small authenticated trust bugs, but both still crossed user boundaries in ways they should not have
cve-2026-48067 came from a scope mismatch in filament AttachAction and AssociateAction
cve-2026-47755 let a low-privileged authenticated user pull another client credentials and totp secrets in itflow
how i reported six shopper cves spanning authorization bypass, privilege escalation, race conditions, idor, and xss
authenticated sharp users could download unrelated laravel storage objects through the generic download endpoint