Skip to content
View 0xBassia's full-sized avatar

Block or report 0xBassia

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xBassia/README.md

> whoami

┌──(root㉿0xbassia)-[~]
└─# cat profile.txt

[+] Name........: Mohamed Bassia
[+] Role........: Security Researcher / Vulnerability Hunter
[+] Specialties.: Source-code auditing, 0-day discovery, web exploitation
[+] Bug classes.: Account takeover, RCE, SSRF, prototype pollution, access control
[+] Credits.....: 13 published CVEs (7 GitHub-reviewed + 6 WPScan)
[+] Advisories..: 4 additional GHSA credits without CVE assignment
[+] Ecosystems..: npm, Go, WordPress, Joomla
[+] Status......: Reading code others trust, finding what they missed

> CVEs --published

13 published CVEs  ·  peak severity 9.8 Critical  ·  npm, Go & WordPress  ·  sorted by severity

CVE Target Severity Vulnerability Class Published
CVE‑2026‑14561 Authora - Easy Login with Mobile Number (< 1.7.7) 🟣 Critical 9.8 Unauthenticated account takeover via OTP disclosure 2026‑07‑20
CVE‑2026‑46510 form-data-objectizer 🔴 High 8.2 Prototype pollution via bracket-notation form keys 2026‑05‑18
CVE‑2026‑45325 @tmlmobilidade/utils 🔴 High 8.2 Prototype pollution in setValueAtPath 2026‑05‑18
CVE‑2026‑45302 parse-nested-form-data 🔴 High 8.2 Prototype pollution via __proto__ in form fields 2026‑05‑18
CVE‑2026‑46509 @ranfdev/deepobj 🔴 High 8.2 Prototype pollution 2026‑05‑14
CVE‑2026‑44483 @rvf/set-get 🔴 High 8.2 Prototype pollution reachable via @rvf/core preprocessFormData 2026‑05‑11
CVE‑2026‑12516 Fediverse Embeds (< 1.5.8) 🔴 High 7.5 Unauthenticated SSRF via media proxy, full read + open proxy 2026‑06‑18
CVE‑2026‑17533 All-in-One WP Migration and Backup (< 7.108) 🔴 High 7.2 Network-wide PHP code execution from a multisite subsite admin 2026‑08‑14
CVE‑2026‑9815 MagicForm (<= 0.1.3) 🔴 High Unauthenticated arbitrary file upload to RCE 2026‑05‑28
CVE‑2026‑9067 Schema & Structured Data for WP & AMP (< 1.60) 🔴 High Unauthenticated arbitrary media upload 2026‑05‑20
CVE‑2026‑12517 Fediverse Embeds (< 1.5.8) 🟠 Medium 5.3 Unauthenticated SSRF via site-info endpoint 2026‑06‑18
CVE‑2026‑47378 nocodb 🟠 Medium Hidden column exposure in public shared views 2026‑06‑05
CVE‑2026‑55671 zitadel/zitadel (Go) 🟢 Low SSRF and denylist bypass in outgoing HTTP components 2026‑06‑18

🟣 Critical  ·  🔴 High  ·  🟠 Medium  ·  🟢 Low  ·  CVSS v3.1 base score shown where assigned

7 GitHub-reviewed CVEs (6 npm + 1 Go) credited via the GitHub Advisory Database  ·  6 WordPress CVEs disclosed through WPScan

> advisories --credited

4 published GitHub Security Advisories  ·  credited as reporter, no CVE assigned

Advisory Target Severity Vulnerability Class Published
GHSA‑mrf2‑rxph‑r28h Kunena Forum (<= 7.0.4) 🔴 High 8.2 Unauthenticated attachment privacy modification, missing CSRF and authorization 2026‑05‑18
GHSA‑wfph‑gf24‑pjqg Kunena Forum (<= 7.0.4) 🟠 Medium 4.3 Missing CSRF token check on the topic rating endpoint 2026‑05‑18
GHSA‑px35‑hwj4‑wqrh Kunena Forum (<= 7.0.4) 🟢 Low 3.5 Arbitrary-user avatar overwrite via missing CSRF check 2026‑05‑18
GHSA‑354h‑gmhv‑mr9c TryGhost/Ghost (< 6.27.0) 🟢 Low 2.7 SSRF in webhook trigger (CWE-918) 2026‑08‑11

> arsenal --list

Source-Code Auditing & SAST

CodeQL Semgrep CodeChecker Manual Review

Vulnerability Research & Exploitation

Burp Suite pwntools Ghidra Frida

Fuzzing & Supply-Chain

AFL++ libFuzzer OSV Dependency Audit

Languages

Python JavaScript TypeScript Go PHP C Bash

> stats --github

> achievements --unlock

Research:   🛡️ 13 published CVEs  ·  📜 4 GHSA advisory credits  ·  🎯 peak 9.8 Critical

GitHub:   🦈 Pull Shark ×2  ·  ⚡ Quickdraw  ·  👥 Pair Extraordinaire  ·  🧊 Arctic Code Vault

> contact --secure

root@0xbassia:~# echo "Hack the planet, responsibly."

Pinned Loading

  1. security-research security-research Public

    Vulnerability disclosures and root-cause analysis. 13 published CVEs across npm, Go and WordPress: account takeover, privilege escalation to RCE, prototype pollution, SSRF and broken access control.