Skip to content

Security research

I build privacy-first software — then I try to break it.

Authorized penetration testing, CVE detection modules submitted to the Metasploit Framework, and peer-reviewed research. Everything here is lab-verified and benign — the goal is to prove a defense holds, not just to claim it does.

Open source

Metasploit detection modules

Auxiliary scanner modules authored and submitted to the Metasploit Framework (Rapid7).

Audiobookshelf

CVE-2025-25205

Auxiliary scanner module detecting a vulnerable Audiobookshelf instance.

View pull requests
Next.js middleware bypass

CVE-2025-29927

Detection for the Next.js middleware authorization bypass.

View pull requests
LiteLLM pre-auth SQL injection

CVE-2026-42208

Detection for an unauthenticated SQL injection in LiteLLM.

View pull requests

Field notes

Penetration testing writeups

Peer-reviewed

Published research

International Journal of Advanced Computer Science and Applications (IJACSA)