Skip to content
View JebeenLee's full-sized avatar

Block or report JebeenLee

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
JebeenLee/README.md

Hi, I'm Jebeen Lee.

Undergraduate student aspiring to become a Web Security Researcher and Penetration Tester.

Interested in:

  • Web Application Security
  • Authentication & Authorization Security
  • Bug Bounty Hunting
  • Open Source Security
  • Vulnerability Research

Security Research

CVEs:

  • CVE-2026-59765 — SSRF via migration asset downloads in Gitea; enables local file read (app.ini) and cloud metadata access. Reporter · High. Advisory
  • CVE-2026-56443 — Public-only token scope bypass on Limited-visibility owners in Gitea (residual after CVE-2026-25714). Reporter · Moderate. Advisory
  • CVE-2026-5038 — Denial of service in Multer. Co-finder · Moderate. Advisory

GHSAs:

  • GHSA-vwqp-7j32-xfg5 — Guests in organizations with restricted user visibility can gain access to profile information of other users. Reporter · Moderate. Advisory
  • GHSA-xw9h-9rcm-hx4m — OpenID Connect authentication ignores the email_verified claim. Reporter·Low. Advisory

Bug Bounty

  • Automattic / WPScan — Received a bug bounty for a valid vulnerability report.

OSS Contributions

  • Fugit — Reported a cron parser bug causing uncaught ZeroDivisionError exceptions and validated the upstream fix.

Activities

  • Hacklipse — Web Part Member of the cybersecurity club at Incheon National University.

Current Focus

  • Web Application Penetration Testing
  • Authentication & Authorization Security
  • Bug Bounty Programs
  • Open Source Vulnerability Research

Pinned Loading

  1. security security Public

    보안 공부

    PHP 2

  2. JebeenLee JebeenLee Public

  3. secret-scanner secret-scanner Public

    프론트엔드 코드에 하드코딩된 민감정보를 배포 전에 찾아내는 셀프 점검 도구

    JavaScript

  4. shinjonghyeop/Capstone shinjonghyeop/Capstone Public

    Go 1