Undergraduate student aspiring to become a Web Security Researcher and Penetration Tester.
Interested in:
- Web Application Security
- Authentication & Authorization Security
- Bug Bounty Hunting
- Open Source Security
- Vulnerability Research
- CVE-2026-59765 — SSRF via migration asset downloads in Gitea; enables local file read (app.ini) and cloud metadata access. Reporter · High. Advisory
- CVE-2026-56443 — Public-only token scope bypass on Limited-visibility owners in Gitea (residual after CVE-2026-25714). Reporter · Moderate. Advisory
- CVE-2026-5038 — Denial of service in Multer. Co-finder · Moderate. Advisory
- GHSA-vwqp-7j32-xfg5 — Guests in organizations with restricted user visibility can gain access to profile information of other users. Reporter · Moderate. Advisory
- GHSA-xw9h-9rcm-hx4m — OpenID Connect authentication ignores the email_verified claim. Reporter·Low. Advisory
- Automattic / WPScan — Received a bug bounty for a valid vulnerability report.
- Fugit — Reported a cron parser bug causing uncaught ZeroDivisionError exceptions and validated the upstream fix.
- Hacklipse — Web Part Member of the cybersecurity club at Incheon National University.
- Web Application Penetration Testing
- Authentication & Authorization Security
- Bug Bounty Programs
- Open Source Vulnerability Research
