Security Researcher and CTF Player
cve-2026-53521 let a stored future ddns profile id turn into another user ddns profile context later in nezha
cve-2026-53634 let authenticated sharp users bypass create authorization through quick creation command endpoints
cve-2026-49355 exposed private work package data through the single meeting agenda item api in openproject
cve-2026-50198 and cve-2026-50199 in wallos were both small authenticated trust bugs, but both still crossed user boundaries in ways they should not have
cve-2026-48067 came from a scope mismatch in filament AttachAction and AssociateAction
cve-2026-47755 let a low-privileged authenticated user pull another client credentials and totp secrets in itflow
how i reported six shopper cves spanning authorization bypass, privilege escalation, race conditions, idor, and xss
authenticated sharp users could download unrelated laravel storage objects through the generic download endpoint
one vulnerability. multiple targets. multiple certificates.
upsolved it tho :p
a writeup of ara7ctf 2026 for/horseman
a complete write up of insanetemple for my beloved juniors
it is easy tho
a writeup of astroctf 2025 rev/ghost