Proof-of-concept write-ups for vulnerabilities I have reported in open-source projects.
Bug bounty submissions, client engagements and undisclosed research are not published here, per disclosure policy.
26 entries across 21 products.
| Product |
Popularity |
ID |
Vulnerability |
Severity |
authentik |
 |
CVE-2026-94609 |
Privilege escalation (CWE-269) via mass-assignable Group.parents and Group.roles |
High |
backstage |
 |
CWE-94 |
Code injection (CWE-94) via the allowlisted extra_templates and theme.custom_dir MkDocs keys in TechDocs |
High |
sentry |
 |
CWE-1236 |
CSV / formula injection (CWE-1236) in the issue-tag and data-export CSV writers |
Low |
gitea |
 |
CVE-2026-73535 |
2FA bypass and persistent account takeover via OpenID identity linking |
High |
portainer |
 |
CVE-2026-72533 |
Docker API proxy authorization bypass via a non-canonical API version prefix |
Critical |
strapi |
 |
CWE-79 XSS |
Stored XSS via Media Library file upload |
High |
strapi |
 |
CWE-918 SSRF |
SSRF in Media Library URL upload |
High |
| Product |
Popularity |
ID |
Vulnerability |
Severity |
firefox |
- |
CVE-2021-4221 |
Address bar spoofing on Firefox for Android via RTL characters |
Medium |
| Product |
Popularity |
ID |
Vulnerability |
Severity |
macos-server |
- |
CVE-2020-9995 |
URL parsing issue in Profile Manager leading to open redirect or cross-site scripting |
Medium |