Dostxodjayev Abdullox

Dostxodjayev Abdullox

Offensive Security Researcher

I audit open-source projects down to a working proof-of-concept and disclose through coordinated channels.

⌘K or / to jump anywhere
About

I read code, find where a trust boundary breaks, and prove the bug against the real running software before I disclose it.

Most of what I find sits in developer tooling. MCP servers, editor plugins, self-hosted apps, browser extensions. The pattern that repeats is untrusted synced content, or an open local port, reaching something it was never meant to.

Everything gets a working proof-of-concept and a coordinated report. A clean audit with no finding is a legitimate result too, and I report it that way.

2CVEs assigned
13advisories published
7certifications
CVEs
WolfStack9.8 Critical
A cluster-authentication secret is hard-coded into every build and published, so any unauthenticated client reaches full remote code execution.
emlog6.8 Medium
The AI-assistant exec endpoint has no CSRF protection, so a visited page can drive SQL execution and take over an admin account.
Published Advisories

A CVE has been requested for each and is pending assignment. Additional findings are in coordinated disclosure.

Certifications
Contact