Based in Vietnam. Mostly just reading source code all day and breaking stuff to see what falls apart. Got lucky digging through django-unicorn β found a state manipulation bug that turned into CVE-2026-31815.
When not hunting bugs, I'm throwing patches at whatever catches my eye on GitHub.
π― Attack Surface:
- π Vuln Research β source auditing, logic bug hunting
- π οΈ OSS Patches β langchain, ray, sktime, tldr-pages, ...
- π§ͺ Tooling β custom audit scripts, automated scanners
- π Stack β Python, Go, JS/TS, Bash
stuff that got merged, stuff still cooking
| Target | Operation | Status |
|---|---|---|
| langchain | π§ Fix tool_outputs validation mismatch in core | |
| ray | π¦ Patch axios dependency in dashboard | |
| sktime | π Fix F1 score division by zero in ClaSP | |
| aibrix | π§Ή Deduplicate session affinity header constants | |
| stella | π§ͺ Add unit tests for array normalizers & color helpers | |
| django-unicorn | π CVE-2026-31815 β State manipulation flaw |
| π Offensive | π‘οΈ Defensive | βοΈ Infrastructure |
|
|
|
|
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β "The quieter you become, the more you are able to hear." β
β β Kali Linux β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ



