Dostxodjayev Abdullox

Dostxodjayev Abdullox

Offensive Security Researcher

I audit open-source projects down to a working proof-of-concept and disclose through coordinated channels.

⌘K or / to jump anywhere
About

I read code, find where a trust boundary breaks, and prove the bug against the real running software before I disclose it.

Most of what I find sits in developer tooling. MCP servers, editor plugins, self-hosted apps, browser extensions. The pattern that repeats is untrusted synced content, or an open local port, reaching something it was never meant to.

Everything gets a working proof-of-concept and a coordinated report. A clean audit with no finding is a legitimate result too, and I report it that way.

14CVEs assigned
2advisories published
7certifications
CVEs
Tugtainer8.1 High
OIDC id_tokens are decoded without checking signature, audience or expiry.
PasteGuard7.6 High
The LLM-proxy routes carry no CORS or CSRF guard and fall back to the server-side API key.
CWE-352CVE-2026-86998copyGHSA-q94x-p9rc-q89fPoC
crw7.5 High
The JS-rendering tiers follow redirects inside the browser stack without re-checking the URL allowlist.
CWE-918CVE-2026-87007copyGHSA-5jp3-339h-vxqwPoC
code-graph-rag7.1 High
The structural-search tools resolve symlinks with no containment check.
CWE-59CVE-2026-87008copyGHSA-85gg-2gfq-q95mPoC
Note Toolbar (Obsidian)7.0 High
A toolbar item that displays a frontmatter property runs it as JavaScript if the value contains a script payload.
CWE-94CVE-2026-87002copyGHSA-q8cw-3m8c-5pf2PoC
emlog6.8 Medium
The AI-assistant exec endpoint has no CSRF protection, so a visited page can drive SQL execution and take over an admin account.
Terrapod6.5 Medium
The GPG-key API is gated on "authenticated" but not "admin."
CWE-862CVE-2026-87006copyGHSA-6qrc-597p-mrp9PoC
Supernote (Obsidian)5.6 Medium
The device-supplied uri field is never checked for ".." before the vault write.
CWE-22CVE-2026-86999copyGHSA-3gx3-r874-5pp4PoC
Gortex5.5 Medium
The indexer walk does not skip symlinked files.
CWE-59CVE-2026-87003copyGHSA-6vhf-4wcm-2r83PoC
ZotLit5.5 Medium
An attachment's path is trusted verbatim on import.
CWE-73CVE-2026-87000copyGHSA-4qh7-66xv-h329PoC
inference-gateway5.4 Medium
The /proxy/:provider/*path route strips any caller Authorization header and injects the operator's own provider key, with no CORS policy or CSRF protection.
CWE-352CVE-2026-87009copyGHSA-5293-fcm6-fh8v
linux-entra-sso5.3 Medium
The SSO-URL check is an unanchored startsWith().
CWE-346CVE-2026-87005copyGHSA-g9vc-5j77-f2cmPoC
OpenLore4.7 Medium
The LLM-derived domain field is not validated before it is used in an output path.
CWE-22CVE-2026-87001copyGHSA-5j8x-q7q6-58j5PoC
Published Advisories

A CVE has been requested for each and is pending assignment. Additional findings are in coordinated disclosure.

Certifications
Contact