Vulnerability Assessment Β· finding, proving and helping fix real security weaknesses
I work in vulnerability assessment: finding real security weaknesses, proving them, and helping vendors fix them. My methods and tooling get better every day, and every finding below was confirmed by the vendor.
| Project | Finding | Severity | Reference |
|---|---|---|---|
| frain-dev/convoy | Insecure Direct Object Reference (IDOR) β CVE-2026-81505 | GHSA-p5vg-v7mj-f6q4 | |
| Swetrix/swetrix | Server-Side Request Forgery (SSRF) β CVE-2026-81506 | GHSA-fcm9-fvcm-3p55 | |
| NangoHQ/nango | SQL Injection | GHSA-8m28-9wcj-v8ww | |
| ubicloud/ubicloud | Information Disclosure (4 commits) | #6399 Β· #6407 | |
| strangerstudios/paid-memberships-pro | Broken Access Control β Sensitive File Exposure | 3.8.8 release Β· #3847 |
6 more findings have been confirmed by their vendors and are waiting for publication. Details will appear here once each vendor publishes.
|
π Every file, not a sample |
π§© A 14-stage review chain |
|
πΈ Reproduced before reported |
π Patch re-testing, private by default |
Maintainers who want a security review of their project are welcome to reach me at tmdals7205@gmail.com. My process has a few distinctive points, and I'm happy to explain them in detail.
Thank you to ubicloud, Countly and Paid Memberships Pro for supporting this research, and for working through each fix together.


