Vulnerability Disclosures
Technical write-ups on critical vulnerabilities (SSRF, Auth Bypasses, Data Leaks) discovered across enterprise platforms and AI infrastructure.
Sarvam AI Security Assessment
Discovered critical vulnerabilities including a blind SSRF and active leaked API keys in production.
Callback URLs in the Speech-to-Text batch processing API lacked hostname and internal IP validation.
Exploited SSRF via STT Batch Job Callback. Identified an active leaked API key granting full access to core NLP services, and discovered CORS misconfigurations.
CtrlB Security Assessment
Identified critical vulnerabilities allowing full remote system compromise on an observability control plane.
Unauthenticated agent registration combined with internal SSRF vulnerabilities exposed internal cloud infrastructure.
Found Critical SSRF via Agent Command Execution, Unauthenticated Agent Registration, and supply-chain RCE via curl-to-bash scripts.
Infoseclabs Security Assessment
Identified Critical authentication flaws and sensitive data exposure on a cybersecurity education platform.
Registration endpoint issued functional JWT session tokens without requiring email verification, alongside unprotected configuration endpoints.
Achieved mass account creation via Email Verification Bypass. Discovered unauthenticated exposure of Stripe Live Keys and OAuth Secrets.
Cyberintelsys Security Assessment
Found multiple attack vectors on a corporate WordPress deployment.
Default configurations and exposed REST APIs facilitated user enumeration and accelerated brute-force attacks.
Discovered WordPress User Enumeration via REST API, XML-RPC Multicall Brute Force vector, and Missing Security Headers.
Megaminds Reconnaissance Report
Discovered critical data exposure and authentication system breakage in an academic portal.
Improper routing and unauthenticated endpoints exposed internal assignment databases and broken authentication flows.
Found Public Assignment Data Exposure, broken Auth endpoints returning HTTP 500s, and unauthenticated Socket.IO connections.
Odoo Reconnaissance Report
Uncovered significant information disclosure across 12 production instances of Odoo ERP.
Improper error handling and unauthenticated APIs leaked detailed server configurations and stack traces.
Identified XMLRPC Stack Trace Leaks, Weblate API Data Exposure (50M+ strings), and Session Info Leakage across multiple instances.