Independent security researcher specializing in discovering critical vulnerabilities (CVSS 8.0+) and responsibly disclosing them to vendors worldwide.
Areas of Expertise
Specialized in Sandbox Escapes and Code Injection in Node.js and server environments.
HTTP Request Smuggling and CRLF Injection analysis in Apache and Nginx.
Auth Bypass, Privilege Escalation, and logical REST API vulnerabilities.
Firewall bypass and Zero-Trust Security Framework vulnerability discovery.
Notable Discoveries
Critical Sandbox Escape vulnerability in the vm2 library for Node.js allowing arbitrary code execution outside the sandbox environment. Reported to multiple vendors before any public disclosure.
HTTP Response Splitting vulnerability in Apache HTTP Server 2.4.58 enabling HTTP response injection via CRLF. Reported to the Apache Security team.
A collection of vulnerabilities discovered across various global systems, some under coordinated responsible disclosure with affected vendors.
Built an automated system linking new NVD vulnerabilities to Bug Bounty programs on HackerOne with DeepSeek AI analysis for each vulnerability.
Ethical Commitment
Responsible disclosure is not a legal obligation — it’s an ethical principle. Every vulnerability I discover is reported to the vendor first.
I give companies adequate time to patch before any public disclosure. My goal is to protect users, not harm systems.
Invite Me to Your Program
Do You Run a Private Bug Bounty Program?
If your company runs a private Bug Bounty program or VDP, I’m interested in joining and contributing to improving your product security.