Skip to content

Latest commit

 

History

14 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation


Typing SVG


GitHub Website HackerOne Bugcrowd

TryHackMe Root-Me Profile Views


whoami

┌──(christbowel㉿kali)-[~]
└─$ cat about.txt

  Name     : Christ Bowel Bouchuen
  Age      : xx
  Location : Darmstadt, Germany
  Uni      : TU Darmstadt — B.Sc. Computer Science
  Focus    : Offensive Security | Vulnerability Research | Bug Bounty

  CVEs Discovered  : 7
  Hall of Fames    : 5 (🇺🇸 State of California · 🇩🇪 Deutsche Telekom · 🌍 Mars VDP · 🇦🇺 RMIT · 🇺🇸 BIA)
  CTF Best Rank    : Top 15/454 — Bugcrowd Black Hat USA CTF 2024 && Top 1 - USD Hacking Night
  Status           : Software Security @ PAYONE GmbH

CVE Highlights

Six highlights below. Thirteen CVEs assigned in total.

  • CVE-2026-56111 · Marlin firmware. Out-of-bounds write; memory corruption validated on real STM32 hardware.
  • CVE-2026-49143 · browserstack-runner. Node VM sandbox escape to unauthenticated RCE. CVSS 8.7.
  • CVE-2026-49144 · browserstack-runner. Path traversal to unauthenticated file read; full host compromise when chained.
  • CVE-2026-67195 · FINOS Perspective. eval injection in PolarsVirtualServer; unauthenticated RCE.
  • CVE-2026-39911 · Hashgraph Guardian. Unsandboxed Function() to authenticated RCE, credential leak, and auth token forgery.
  • CVE-2024-29643 · Croogo CMS. Host Header Injection to RCE.

Seven more across Guardian, Perspective, and other targets.

Reported and Fixed

Vulnerabilities disclosed and patched by maintainers, no CVE assigned.

  • OWASP Dependency-Track · IDOR, confused deputy, and multi-team permission union across v4.14 and v5 (Hyades). Coordinated with maintainers and VulnCheck.
  • Symfony · Deserialization trampoline through nested unserialize(), bypassing allowed_classes. Coordinated with a core maintainer.

Selected Work

  • OSDC (Open Source Daily Catch) · Automated silent-patch detection. Scrapes the GitHub Advisory Database and diffs quiet fixes to surface n-days before they go public. The pipeline behind much of the CVE output above.
  • Diffuse · Decentralized AI inference protocol in Rust. TEE, Shamir secret sharing for prompt fragmentation, and ZK execution proofs, so inference runs without any single party ever seeing plaintext. Architecture and specification stage.

Elsewhere

1st place, usd Hacking Night CTF. Halls of Fame across public and federal disclosure programs. Coordinated Vulnerability Disclosure through VulnCheck.

📊 Stats



GitHub Streak


📈 Activity Graph

Activity Graph



♟️ Chess move of the day

Chess.com

Schach Club · TU Darmstadt ♟️


💬 Quote

Readme Quotes


🌍 Langues

🇫🇷 Français 🇩🇪 Deutsch 🇬🇧 English
Langue maternelle C1 Fließend Fluent

"Security is not a product, but a process."

About

whoami

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors