Security researcher. I find and report vulnerabilities in software people actually run β web2 and web3.
Every claim on this page links to something you can open.
GHSA-858h-whjf-mvg5 Β· CVE-2026-102827 β simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p, --exe) β command execution
- High β CVSS 3.1 score 8.1 (
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) Β· CWE-77 + CWE-88 - Affects
simple-git <= 3.36.0(npm) Β· patched in 4.0.0 - Fix: steveukx/git-js#1193 Β· commit
98864c6 - CVE record published 2026-09-29 Β· in the GitHub Advisory Database 2026-10-05 Β· credited reporter
- The guard compared option names by exact spelling; git accepts any unambiguous prefix. So
--receive-pand--exewere unknown strings to the guard and--receive-pack/--execto git β the residual of CVE-2026-28291, the fix the guard was added for. - Several researchers hit this independently: the finder credit is anir0y's, and the advisory lists me among the reporters. My report went in on 2026-08-10.
GHSA-v5mv-p594-2x33 Β· CVE-2026-69246 β Noncanonical host can bypass host-based checks in guzzlehttp/guzzle
- High β CVSS 3.1 score 7.2 (
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) Β· CWE-180 + CWE-436 + CWE-918 - Affects
< 7.15.2and>= 8.0.0, < 8.0.1Β· patched in 7.15.2 and 8.0.1 - Advisory published 2026-07-26 Β· CVE record 2026-08-03 Β· credited reporter
GHSA-859q-jpx8-p5mm β yarl silently strips default-ignorable code points from the host
- Medium β CWE-436 (Interpretation Conflict) + CWE-918 (SSRF)
- Affects
yarl <= 1.24.2Β· patched in 1.24.5 - Fix: aio-libs/yarl#1801 β "Reject hosts with Unicode default-ignorable code points"
- CVE-2026-86052 issued by GitHub (CNA) on 2026-09-05; the record stays reserved until the maintainers publish the advisory
- Accepted; advisory pending publication, so the release and the patch commit are the public record
Immunefi β ENS Audit Competition β 1 Critical, confirmed by the project
- Critical Β· Confirmed Β· Chief Finding. Submission #92925, submitted 2026-09-13. The project's status on the report reads "The project believes the report is valid and will be rewarded."
- Scope:
immunefi-team/audit-comp-ensβ the competition repository, and the report's own declared target. - No mechanism, proof of concept or report text appears here, and none will while the finding is unpublished. Immunefi keeps submission pages behind authentication, so β as with the Cantina entry below β there is no openable record of this one yet. What is openable is the scope above.
Sherlock β $4.15K total, #982 all-time Β· 2 payouts Β· 1Γ 2nd place Β· 2Γ top 10 Β· 2Γ top 25
Metric β rank #4 Β· 1,611.03 USDC
- Medium β Missing zero-output guard in
SwapMath's exact-input swaps lets an attacker corruptcurPosInBinfor free and profit on subsequent real trades - It is the unpatched sibling of Zellic 3.4: that fix (
57674bdd) covered the exact-output functions only, and the exact-input path was left live.
Tare β 2nd place Β· 2,535.04 USDC
Cantina β 1 high-severity finding on the public profile
doppler-contracts (Whetstone) β Reentrancy in RehypeDopplerHookInitializer._onSwap:
permissionless cross-user theft of shared accrued fees
- High. The hook is a shared singleton on Base (
0xBF4195ab0B03e1eB3345dd1e83BeD7650b1ed123) whose balance commingles the accrued fees of every pool that uses it. - On each swap the hook performs a DirectBuyback to a pool-configured β and attacker-controllable β
buybackDstbefore zeroinggetHookFees[poolId].fees0/fees1, and_onSwapcarries no reentrancy guard. Re-entering therefore pays out against fees that belong to other pools. - Filed 2026-07-21 Β· closed duplicate of an earlier report, which the project has since fixed. This programme rewards the first reporter only, so a duplicate is not eligible β the bug was real and is gone; the credit for it is not mine.
- Cantina keeps finding pages behind authentication, so the openable record here is the profile's severity counter rather than the write-up itself.
The Guzzle and yarl advisories are the same bug class in two different language ecosystems, found by the same method: a URL library and the code that validates it disagree about what the host is. The validator inspects one host string; the client then connects somewhere else. Guzzle is PHP, yarl is Python β the class does not care about the language.
That is the work: pick a transformation that runs before a security decision, measure what it actually does to its whole input space instead of guessing, and then look for a consumer that re-derives the value differently.
The simple-git advisory is the same shape on a different axis. The guard read an option name by its exact spelling; the parser behind it, git, accepts any unambiguous prefix. One value, two readers, and the security decision was made by the stricter of the two.
The Metric finding is the same habit pointed at a patch rather than at a parser: read what the fix actually changed, then go looking for the call sites it did not reach. A remediation is a boundary someone drew by hand, and hands miss siblings.
- Nothing is reported until it has been executed. A conclusion from reading source is a hypothesis. It stays a hypothesis until a test drives the real code and fails without the bug.
- Every negative result needs a positive control. If a search returns nothing, I first prove the search can return something.
- The impact ladder gets climbed all the way, and where a rung does not hold, the report says so.
Findings like the ones above take weeks of unpaid execution β building the lab, running the controls, and writing the negative results down as carefully as the positive ones. If any of it saved you time, a coffee is genuinely appreciated.
EVM address β Ethereum and EVM-compatible chains:
0x5A1d2EFAeef4cd4c8C4F9d8D78B10fbE8b22B814
No obligation, and it changes nothing about what gets reported or to whom.
π« admin@researchcti.cyou