Security Researcher specializing in web application penetration testing and cloud security research.
- Web Application Pentesting
- Cloud VRP β Currently focused on Google Cloud Bug Bounty, ranked ~364th (Top 20%) on the leaderboard
- SSRF Exposes OpenAI API Keys in berriai/litellm
- XSS via chat information tooltip in open-webui/open-webui
- RCE by Non-Admin Users via CSRF in open-webui/open-webui
- Possible userinfo Leakage in
URI.join/URI#mergein ruby - Possible SSRF and Credential Leakage via Absolute URL in axios Requests
- Potential SSRF Vulnerability in httparty Leading to API Key Leakage in httparty






