About
I read code, find where a trust boundary breaks, and prove the bug against the real running software before I disclose it.
Most of what I find sits in developer tooling. MCP servers, editor plugins, self-hosted apps, browser extensions. The pattern that repeats is untrusted synced content, or an open local port, reaching something it was never meant to.
Everything gets a working proof-of-concept and a coordinated report. A clean audit with no finding is a legitimate result too, and I report it that way.
14CVEs assigned
2advisories published
7certifications
CVEs
WolfStack9.8 Critical
A cluster-authentication secret is hard-coded into every build and published, so any unauthenticated client reaches full remote code execution.
Tugtainer8.1 High
OIDC id_tokens are decoded without checking signature, audience or expiry.
PasteGuard7.6 High
The LLM-proxy routes carry no CORS or CSRF guard and fall back to the server-side API key.
crw7.5 High
The JS-rendering tiers follow redirects inside the browser stack without re-checking the URL allowlist.
code-graph-rag7.1 High
The structural-search tools resolve symlinks with no containment check.
Note Toolbar (Obsidian)7.0 High
A toolbar item that displays a frontmatter property runs it as JavaScript if the value contains a script payload.
emlog6.8 Medium
The AI-assistant exec endpoint has no CSRF protection, so a visited page can drive SQL execution and take over an admin account.
Terrapod6.5 Medium
The GPG-key API is gated on "authenticated" but not "admin."
Supernote (Obsidian)5.6 Medium
The device-supplied uri field is never checked for ".." before the vault write.
Gortex5.5 Medium
The indexer walk does not skip symlinked files.
ZotLit5.5 Medium
An attachment's path is trusted verbatim on import.
inference-gateway5.4 Medium
The /proxy/:provider/*path route strips any caller Authorization header and injects the operator's own provider key, with no CORS policy or CSRF protection.
linux-entra-sso5.3 Medium
The SSO-URL check is an unanchored startsWith().
OpenLore4.7 Medium
The LLM-derived domain field is not validated before it is used in an output path.
Published Advisories
A CVE has been requested for each and is pending assignment. Additional findings are in coordinated disclosure.
Certifications
Contact