Skip to content
View javokhir-sec's full-sized avatar

Block or report javokhir-sec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
javokhir-sec/README.md
header

typing



👹 $ whoami

I'm an Offensive Security Researcher and Bug Bounty Hunter focused on web application security and source-code auditing of open-source software. I find vulnerabilities, confirm them with working PoCs, and report through coordinated / responsible disclosure — often contributing the fix as a PR.

  • 🔭 Auditing open-source web apps (PHP / Python / JavaScript)
  • 🛡️ Specializing in: XSS, SQL Injection, SSRF, LFI, Path Traversal, Broken Access Control, CSRF, Auth Bypass
  • 🐛 Bug Bounty: Okta (Bugcrowd), Anthropic (HackerOne), Agoda
  • 🎓 B.Sc. Computer Engineering — Fergana State Technical University (2020–2025)
  • 🌍 Based in Uzbekistan (UTC +05:00)
  • 🏆 Leantime Contributor — 5 security PRs submitted to Leantime OSS
  • 📡 CVE via: VulnCheck CNA — 4 Published + 5 Review + 4 SuiteCRM Triage

"The quieter you become, the more you are able to hear."



🛠️ Open Source Projects



🧰 Arsenal

skills


🏆 Advisories & CVEs

🏆 ADVISORIES & CVEs — 4 PUBLISHED · 4 SuiteCRM Triage · 5 VulnCheck Review ▼

✅ PUBLISHED (4 CVEs)

# CVE Product Type CVSS
1 CVE-2026-66412 Leantime ⭐10k+ IDOR (getMilestone) 7.5
2 CVE-2026-66414 Leantime ⭐10k+ Open Redirect 6.1
3 CVE-2026-66415 Leantime ⭐10k+ SSRF + LFI 8.8
4 CVE-2026-66416 Leantime ⭐10k+ CSRF Disabled 8.8

⏳ SuiteCRM — GitHub Security Advisories (Triage)

# GHSA Type CVSS Internal
1 GHSA-xq73-pwv7-jcvg Unauth SQLi (GeneratePassword) 9.8 SCRMBT-480
2 GHSA-m4vv-h45q-rvvf File Upload Case Bypass 8.8 SCRMBT-481
3 GHSA-w59p-wvpf-gmm5 File Upload GD Bypass RCE 8.8 SCRMBT-482
4 GHSA-h87x-44w6-3q7f Unauth XSS (WebToLead) 8.2 SCRMBT-483

⏳ VulnCheck — Review (July 29)

# Target Type CVSS
1 eGov SmartCity Struts2 RCE (OGNL) 10.0
2 Tesla Vehicle CMD JWT No Signature Check 8.8
3 OzonTech file.d Missing Auth (10+ endpoints) 8.2
4 Gojek Darkroom Path Traversal 7.5
5 Kaspersky KLara No Rate Limit 6.5
### 🎓 Certifications






🐍 Contribution Snake

snake


☕ Support My Research


📫 Let's Connect

random quote

Building a safer open-source ecosystem, one vulnerability at a time.


📈 Stats & Activity

🏆 GITHUB ACHIEVEMENTS — click to expand ▼

📊 GITHUB STATS — click to expand ▼

🔥 WAKATIME (LAST 30 DAYS) — click to expand ▼

WakaTime stats

📈 CONTRIBUTION ACTIVITY — click to expand ▼

Pinned Loading

  1. PromptFuzzer PromptFuzzer Public

    Automated prompt injection fuzzer for LLM applications. Test your AI apps against OWASP Top 10 for LLMs — jailbreak, system prompt extraction, RCE

    1

  2. AI-BugHunter AI-BugHunter Public

    🤖 AI-powered vulnerability discovery assistant — automated recon + intelligent scanning for bug bounty hunters

    Python 1

  3. BugBounty-CLI BugBounty-CLI Public

    All-in-one bug bounty reconnaissance CLI — subdomain enum, port scan, URL collection, vulnerability scanning. Automate your recon workflow

    1

  4. awesome-bugbounty-resources awesome-bugbounty-resources Public

    Curated list of bug bounty resources: tools, writeups, methodology, platforms, and learning materials for aspiring bug bounty hunters

    Shell 1 1

  5. CVE-PoC-Hub CVE-PoC-Hub Public

    🛡️ CVE Proof-of-Concept Hub — 21 security advisories · 80+ vulnerabilities · 19 CVEs under review · 1 PUBLISHED (CVE-2026-66412)

    Python 1 1

  6. shodan-scanner shodan-scanner Public

    🌍 Advanced Shodan & Censys CLI — hunt exposed services, IoT devices, vulnerable hosts

    1