Independent security researcher working on coordinated vulnerability disclosure.
I audit open-source projects and self-hosted software and report issues through each project's responsible-disclosure channel. Focus areas:
- Authorization & access control β broken access control, IDOR, missing permission checks
- Web & API security β SSRF, injection, auth/scope bypass, webhook/IPN authenticity
- Secrets & supply chain β secret exposure in tooling/IaC, insecure defaults in CI/build
- Patchstack β researcher profile (published advisory: Simple Cloudflare Turnstile β€ 1.42.1 β Content Injection, CVSS 6.5)
- Intigriti β profile
- HackerOne β profile
- tfsensitive β a Go (
go/ast) linter that catches a silent Terraform SDKv2 footgun: aSensitive: truefield nested inside a Computed-onlyTypeList/TypeSet, which SDKv2 drops so the secret lands in plan/state. MIT.
- chirpstack/chirpstack #1024 β restore a missing
ValidateGatewaysAccessauthorization check in the gateway API - datalayer/jupyter-mcp-server #453 β bind the streamable-HTTP server to loopback by default and decouple CORS
- aiven/aiven-client #480 β restrict file mode on downloaded
service.key/service.cert - dmpe/terraform-provider-storagegrid #57 β mark
secret_access_keyasSensitiveon the S3-key resources (prevents secret exposure in plan/state) - kamailio/kamailio-credits #11 β credited for a security report
I also file coordinated-disclosure reports to many other projects (kept private while under embargo) and run small security labs / PoCs for CI/CD and IaC issue patterns.
I follow coordinated vulnerability disclosure: reports go to the project's designated security channel first, I honor requested embargoes (typically up to 90 days), and I publish details only after a fix ships or the embargo ends. Reports include a concrete proof-of-concept and a suggested fix.
If my work has helped your project, sponsorship funds continued security research and responsible disclosure. Thank you π
For security matters, please use the relevant project's security channel.