Security Research
A collection of high-impact vulnerability research and disclosures.
Sarvam-105B Security Assessment: Identity Fragility
Disclosed a vulnerability chain where standard API usage patterns caused the Sarvam-105B model to revert to competitor identities, alongside a side-channel reasoning leak.
Critical Liveness Bypass & Admin Takeover
Discovered a critical vulnerability chain allowing unauthenticated bypass of biometric liveness detection and moderator takeover of private video conference rooms.
Administrative Identity Flow & 2FA Bypass Chain
Exploited a breakdown in environment isolation to bypass 2FA via a hardcoded staging secret, enabling extraction of unmasked Highly Sensitive PII.
Non-Superuser Access to pg_shadow Password Hashes
Found an issue where any authenticated database user could extract SCRAM-SHA-256 password hashes for all users and map complete internal infrastructure.
Mass Information Disclosure of 10,000+ Internal Player Records
Disclosed a Next.js data over-exposure vulnerability leading to the mass leakage of internal player records.
Missing Authorization on Mass Email Subscription Manipulation
Identified an endpoint allowing valid API keys to change email subscription states for arbitrary emails globally at ~2,500 addresses/second.
CORS Misconfiguration Allows Cross-Origin Data Theft
Identified a misconfiguration on the PingOne API where the origin header is reflected with credentials enabled, allowing authenticated cross-origin data exfiltration.
Unauthenticated Access to Internal Service Registry
Discovered a public endpoint exposing the entire Myntra API infrastructure, including microservice names, team IDs, and historical SSRF/XSS payloads.
Unauthenticated Data Exfiltration via Salesforce Aura
Leveraged a misconfigured Salesforce Community guest profile to access the Aura controller, exposing internal employee records and files.
Critical Information Disclosure via WAF Bypass
Reported an exposed developer file (info.aspx) accessible via a WAF bypass technique.
Unauthenticated Sanity.io API Access Leaking Config
Found unprotected access to Sanity.io APIs that leaked internal architecture details and configuration files.
Widespread Information Disclosure via SOS Buckets
Identified over 100 publicly listable SOS buckets containing sensitive resources across the bug bounty scope.
Potential AWS S3 Bucket Takeover via JS Bundle
Found an unregistered AWS S3 bucket explicitly referenced in the UAT application's JavaScript bundle, exposing it to hijacking.