whoami
hi, security researcher based in tokyo. I’m interested in many things, on which i sometimes blog about.
cves
full list here.
- CVE-2026-41448 (9.4) auth bypass via path traversal in AdGuard Home
- CVE-2026-56115 (8.8) missing admin check in bootimus’ jwt middleware
- CVE-2026-3739 (8.5) idor on message threads in suitenumerique/messages
- CVE-2026-35025 (8.1) acl bypass in ProFTPD via a
/proc/self/root prefix
- CVE-2026-23679 (6.2) null deref in libusb parsing malformed descriptors
freelance services
if you are looking to hire someone remotely, and your time is flexible, you should consider hiring me !
you can click here for more info
talks
ongoing public projects
archived projects
djnn.sh
offensive security & software engineering