Emergency
Independent Security Researcher
CYBER755
Bug Bounty Hunter · Jordan

Independent security researcher specializing in discovering critical vulnerabilities (CVSS 8.0+) and responsibly disclosing them to vendors worldwide.

🛡️ Responsible Disclosure 🎯 CVSS 8.0+ Focus 📍 Jordan · MENA h1 HackerOne: cyber755
150+Vulnerabilities Discovered
9.8Highest CVSS Recorded
100%Always Responsible Disclosure
// Expertise Areas

Areas of Expertise

💥
Remote Code Execution (RCE)

Specialized in Sandbox Escapes and Code Injection in Node.js and server environments.

Sandbox EscapeCode InjectionVM2 / Node.js
🌐
Web Server Vulnerabilities

HTTP Request Smuggling and CRLF Injection analysis in Apache and Nginx.

HTTP SmugglingCRLF InjectionApache / Nginx
🔐
Web Application Security

Auth Bypass, Privilege Escalation, and logical REST API vulnerabilities.

Auth BypassPrivilege EscalationIDOR / SSRF
🛡️
Network & Infrastructure Security

Firewall bypass and Zero-Trust Security Framework vulnerability discovery.

Firewall BypassZero-Trust FlawsNetwork Protocol
// Notable Discoveries

Notable Discoveries

CVE-2026-24781CVSS 9.8 Critical
VM2 Sandbox Escape — Remote Code Execution

Critical Sandbox Escape vulnerability in the vm2 library for Node.js allowing arbitrary code execution outside the sandbox environment. Reported to multiple vendors before any public disclosure.

CVE-2026-33523CVSS 6.5 Medium
Apache HTTP Response Splitting — CRLF Injection

HTTP Response Splitting vulnerability in Apache HTTP Server 2.4.58 enabling HTTP response injection via CRLF. Reported to the Apache Security team.

Private Repository
150+ Vulnerabilities in Private Repo

A collection of vulnerabilities discovered across various global systems, some under coordinated responsible disclosure with affected vendors.

Automation · 2026
Bug Bounty Scout — Automated Matching System

Built an automated system linking new NVD vulnerabilities to Bug Bounty programs on HackerOne with DeepSeek AI analysis for each vulnerability.

// Disclosure Philosophy

Ethical Commitment

Responsible disclosure is not a legal obligation — it’s an ethical principle. Every vulnerability I discover is reported to the vendor first.

I give companies adequate time to patch before any public disclosure. My goal is to protect users, not harm systems.

// Bug Bounty Platforms

Invite Me to Your Program

H1
HackerOne — cyber755
hackerone.com/cyber755
● Active

Do You Run a Private Bug Bounty Program?

If your company runs a private Bug Bounty program or VDP, I’m interested in joining and contributing to improving your product security.

© 2026 Cyber755 · Independent Security Researcher · Jordan · cs755.com