Skip to content
View bilguunbicktivism's full-sized avatar
πŸ’­
24/7 Research CVE & BugHunting
πŸ’­
24/7 Research CVE & BugHunting

Block or report bilguunbicktivism

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bilguunbicktivism/README.md

Bicktivism Z

Security researcher. I find and report vulnerabilities in software people actually run β€” web2 and web3.

simple-git β€” CVE-2026-102827, High, CVSS 8.1 guzzlehttp/guzzle β€” CVE-2026-69246, High, CVSS 7.2 aio-libs/yarl β€” CVE-2026-86052 reserved, Medium, patched in 1.24.5 Sherlock β€” $4.15K, 1x 2nd place, 2x top 10 Immunefi β€” Critical, confirmed Cantina β€” 1 high-severity finding credited reporter Buy me a coffee

Every claim on this page links to something you can open.


Published advisories

GHSA-858h-whjf-mvg5 Β· CVE-2026-102827 β€” simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p, --exe) β†’ command execution

  • High β€” CVSS 3.1 score 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) Β· CWE-77 + CWE-88
  • Affects simple-git <= 3.36.0 (npm) Β· patched in 4.0.0
  • Fix: steveukx/git-js#1193 Β· commit 98864c6
  • CVE record published 2026-09-29 Β· in the GitHub Advisory Database 2026-10-05 Β· credited reporter
  • The guard compared option names by exact spelling; git accepts any unambiguous prefix. So --receive-p and --exe were unknown strings to the guard and --receive-pack / --exec to git β€” the residual of CVE-2026-28291, the fix the guard was added for.
  • Several researchers hit this independently: the finder credit is anir0y's, and the advisory lists me among the reporters. My report went in on 2026-08-10.

GHSA-v5mv-p594-2x33 Β· CVE-2026-69246 β€” Noncanonical host can bypass host-based checks in guzzlehttp/guzzle

  • High β€” CVSS 3.1 score 7.2 (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) Β· CWE-180 + CWE-436 + CWE-918
  • Affects < 7.15.2 and >= 8.0.0, < 8.0.1 Β· patched in 7.15.2 and 8.0.1
  • Advisory published 2026-07-26 Β· CVE record 2026-08-03 Β· credited reporter

GHSA-859q-jpx8-p5mm β€” yarl silently strips default-ignorable code points from the host

  • Medium β€” CWE-436 (Interpretation Conflict) + CWE-918 (SSRF)
  • Affects yarl <= 1.24.2 Β· patched in 1.24.5
  • Fix: aio-libs/yarl#1801 β€” "Reject hosts with Unicode default-ignorable code points"
  • CVE-2026-86052 issued by GitHub (CNA) on 2026-09-05; the record stays reserved until the maintainers publish the advisory
  • Accepted; advisory pending publication, so the release and the patch commit are the public record

Audit contests

Immunefi β€” ENS Audit Competition β€” 1 Critical, confirmed by the project

  • Critical Β· Confirmed Β· Chief Finding. Submission #92925, submitted 2026-09-13. The project's status on the report reads "The project believes the report is valid and will be rewarded."
  • Scope: immunefi-team/audit-comp-ens β€” the competition repository, and the report's own declared target.
  • No mechanism, proof of concept or report text appears here, and none will while the finding is unpublished. Immunefi keeps submission pages behind authentication, so β€” as with the Cantina entry below β€” there is no openable record of this one yet. What is openable is the scope above.

Sherlock β€” $4.15K total, #982 all-time Β· 2 payouts Β· 1Γ— 2nd place Β· 2Γ— top 10 Β· 2Γ— top 25

Metric β€” rank #4 Β· 1,611.03 USDC

  • Medium β€” Missing zero-output guard in SwapMath's exact-input swaps lets an attacker corrupt curPosInBin for free and profit on subsequent real trades
  • It is the unpatched sibling of Zellic 3.4: that fix (57674bdd) covered the exact-output functions only, and the exact-input path was left live.

Tare β€” 2nd place Β· 2,535.04 USDC


Bug bounties

Cantina β€” 1 high-severity finding on the public profile

doppler-contracts (Whetstone) β€” Reentrancy in RehypeDopplerHookInitializer._onSwap: permissionless cross-user theft of shared accrued fees

  • High. The hook is a shared singleton on Base (0xBF4195ab0B03e1eB3345dd1e83BeD7650b1ed123) whose balance commingles the accrued fees of every pool that uses it.
  • On each swap the hook performs a DirectBuyback to a pool-configured β€” and attacker-controllable β€” buybackDst before zeroing getHookFees[poolId].fees0/fees1, and _onSwap carries no reentrancy guard. Re-entering therefore pays out against fees that belong to other pools.
  • Filed 2026-07-21 Β· closed duplicate of an earlier report, which the project has since fixed. This programme rewards the first reporter only, so a duplicate is not eligible β€” the bug was real and is gone; the credit for it is not mine.
  • Cantina keeps finding pages behind authentication, so the openable record here is the profile's severity counter rather than the write-up itself.

The common thread

The Guzzle and yarl advisories are the same bug class in two different language ecosystems, found by the same method: a URL library and the code that validates it disagree about what the host is. The validator inspects one host string; the client then connects somewhere else. Guzzle is PHP, yarl is Python β€” the class does not care about the language.

That is the work: pick a transformation that runs before a security decision, measure what it actually does to its whole input space instead of guessing, and then look for a consumer that re-derives the value differently.

The simple-git advisory is the same shape on a different axis. The guard read an option name by its exact spelling; the parser behind it, git, accepts any unambiguous prefix. One value, two readers, and the security decision was made by the stricter of the two.

The Metric finding is the same habit pointed at a patch rather than at a parser: read what the fix actually changed, then go looking for the call sites it did not reach. A remediation is a boundary someone drew by hand, and hands miss siblings.


How I work

  • Nothing is reported until it has been executed. A conclusion from reading source is a hypothesis. It stays a hypothesis until a test drives the real code and fails without the bug.
  • Every negative result needs a positive control. If a search returns nothing, I first prove the search can return something.
  • The impact ladder gets climbed all the way, and where a rung does not hold, the report says so.

Support the work

Findings like the ones above take weeks of unpaid execution β€” building the lab, running the controls, and writing the negative results down as carefully as the positive ones. If any of it saved you time, a coffee is genuinely appreciated.

EVM address β€” Ethereum and EVM-compatible chains:

0x5A1d2EFAeef4cd4c8C4F9d8D78B10fbE8b22B814

No obligation, and it changes nothing about what gets reported or to whom.


πŸ“« admin@researchcti.cyou

Popular repositories Loading

  1. bilguunbicktivism bilguunbicktivism Public

    Security research β€” published advisories in simple-git, guzzlehttp/guzzle and yarl

  2. filament filament Public

    Forked from google/filament

    Filament is a real-time physically based rendering engine for Android, iOS, Windows, Linux, macOS, and WebGL2

    C++

  3. nginx nginx Public

    Forked from nginx/nginx

    The official NGINX Open Source repository.

    C

  4. continuous-integration continuous-integration Public

    Forked from bazelbuild/continuous-integration

    Bazel's Continuous Integration Setup

    Python

  5. aqua aqua Public

    Forked from 1inch/aqua

    Shared liquidity layer protocol

    Solidity