Skip to content
View GrayOM's full-sized avatar
🏠
Working from home
🏠
Working from home

Sponsors

@ubicloud

Block or report GrayOM

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
GrayOM/README.md

Hi, I'm GrayOM πŸ‘‹

Vulnerability Assessment Β· finding, proving and helping fix real security weaknesses


Published CVEs Credited findings In coordinated disclosure

Contact


I work in vulnerability assessment: finding real security weaknesses, proving them, and helping vendors fix them. My methods and tooling get better every day, and every finding below was confirmed by the vendor.

πŸ” Published findings

Project Finding Severity Reference
frain-dev/convoy Insecure Direct Object Reference (IDOR) β€” CVE-2026-81505 High GHSA-p5vg-v7mj-f6q4
Swetrix/swetrix Server-Side Request Forgery (SSRF) β€” CVE-2026-81506 High GHSA-fcm9-fvcm-3p55
NangoHQ/nango SQL Injection High GHSA-8m28-9wcj-v8ww
ubicloud/ubicloud Information Disclosure (4 commits) Low #6399 Β· #6407
strangerstudios/paid-memberships-pro Broken Access Control β€” Sensitive File Exposure Medium 3.8.8 release Β· #3847

⏳ In coordinated disclosure

6 more findings have been confirmed by their vendors and are waiting for publication. Details will appear here once each vendor publishes.

πŸ› οΈ How I work

πŸ” Every file, not a sample
Most AI-agent audits read only part of a codebase, typically the files that look most important. My review runs an exhaustive chain that covers every file of the project, so issues outside the "core" are not missed.

🧩 A 14-stage review chain
Each project goes through a fixed sequence of stages, and each stage hands its results to the next: from running the software and measuring what each kind of user can reach, through full-tree analysis, to the final verified report.

πŸ“Έ Reproduced before reported
Nothing is reported until it has been reproduced and captured on screen. That keeps false positives rare, and every report comes with a working reproduction, a negative control and the exact code path.

πŸ” Patch re-testing, private by default
I re-test the vendor's patch before it ships and report it when the fix is incomplete. Nothing is published until the vendor is ready.

πŸ“¬ Security review for your open-source project

Maintainers who want a security review of their project are welcome to reach me at tmdals7205@gmail.com. My process has a few distinctive points, and I'm happy to explain them in detail.


πŸ™ Thanks

Thank you to ubicloud, Countly and Paid Memberships Pro for supporting this research, and for working through each fix together.

Pinned Loading

  1. Availability-Low-Reconnaissance Availability-Low-Reconnaissance Public

    Python

  2. mobile_allinone mobile_allinone Public

    Python

  3. Agent_Guidance Agent_Guidance Public

    Python

  4. Hack_guidance Hack_guidance Public

    TypeScript