I'm an Offensive Security Researcher and Bug Bounty Hunter focused on web application security and source-code auditing of open-source software. I find vulnerabilities, confirm them with working PoCs, and report through coordinated / responsible disclosure — often contributing the fix as a PR.
- 🔭 Auditing open-source web apps (PHP / Python / JavaScript)
- 🛡️ Specializing in: XSS, SQL Injection, SSRF, LFI, Path Traversal, Broken Access Control, CSRF, Auth Bypass
- 🐛 Bug Bounty: Okta (Bugcrowd), Anthropic (HackerOne), Agoda
- 🎓 B.Sc. Computer Engineering — Fergana State Technical University (2020–2025)
- 🌍 Based in Uzbekistan (UTC +05:00)
- 🏆 Leantime Contributor — 5 security PRs submitted to Leantime OSS
- 📡 CVE via: VulnCheck CNA — 4 Published + 5 Review + 4 SuiteCRM Triage
"The quieter you become, the more you are able to hear."
🏆 ADVISORIES & CVEs — 4 PUBLISHED · 4 SuiteCRM Triage · 5 VulnCheck Review ▼
| # | CVE | Product | Type | CVSS |
|---|---|---|---|---|
| 1 | CVE-2026-66412 | Leantime ⭐10k+ | IDOR (getMilestone) | 7.5 |
| 2 | CVE-2026-66414 | Leantime ⭐10k+ | Open Redirect | 6.1 |
| 3 | CVE-2026-66415 | Leantime ⭐10k+ | SSRF + LFI | 8.8 |
| 4 | CVE-2026-66416 | Leantime ⭐10k+ | CSRF Disabled | 8.8 |
| # | GHSA | Type | CVSS | Internal |
|---|---|---|---|---|
| 1 | GHSA-xq73-pwv7-jcvg | Unauth SQLi (GeneratePassword) | 9.8 | SCRMBT-480 |
| 2 | GHSA-m4vv-h45q-rvvf | File Upload Case Bypass | 8.8 | SCRMBT-481 |
| 3 | GHSA-w59p-wvpf-gmm5 | File Upload GD Bypass RCE | 8.8 | SCRMBT-482 |
| 4 | GHSA-h87x-44w6-3q7f | Unauth XSS (WebToLead) | 8.2 | SCRMBT-483 |
| # | Target | Type | CVSS |
|---|---|---|---|
| 1 | eGov SmartCity | Struts2 RCE (OGNL) | 10.0 |
| 2 | Tesla Vehicle CMD | JWT No Signature Check | 8.8 |
| 3 | OzonTech file.d | Missing Auth (10+ endpoints) | 8.2 |
| 4 | Gojek Darkroom | Path Traversal | 7.5 |
| 5 | Kaspersky KLara | No Rate Limit | 6.5 |
Building a safer open-source ecosystem, one vulnerability at a time.
📈 CONTRIBUTION ACTIVITY — click to expand ▼

