Independent security researcher specializing in discovering critical vulnerabilities (CVSS 8.0+) and reporting them responsibly to vendors worldwide.
Areas of Expertise
Specializing in Sandbox Escapes and Code Injection in Node.js environments and server-side applications.
Analysis of HTTP Request Smuggling and CRLF Injection in Apache and Nginx servers.
Discovering Authentication Bypass, Privilege Escalation, and REST API logical flaws.
Firewall Bypass and detection of Zero-Trust Security Framework implementation flaws.
Notable Findings
Critical Sandbox Escape vulnerability in the Node.js vm2 library allowing arbitrary code execution outside the isolated environment. Reported to multiple vendors before any public disclosure.
HTTP Response Splitting vulnerability in Apache HTTP Server 2.4.58 enabling HTTP response injection via CRLF sequences. Reported to the Apache Security Team.
A collection of vulnerabilities discovered across various global systems. Some are currently under coordinated responsible disclosure with the affected vendors.
Built an automated system linking new NVD vulnerabilities to HackerOne Bug Bounty programs with DeepSeek AI analysis for each CVE and estimated bounty ranges.
Ethical Commitment
Responsible Disclosure Advocate. Every vulnerability reported ethically to vendors before any public mention.
I give companies sufficient time to patch before any public disclosure. My goal is to protect users, not to damage systems.
Invite Me to Your Program
Do You Have a Private Bug Bounty Program?
If your company has a private Bug Bounty program or VDP, I’m interested in joining and contributing to improving the security of your products.