Application Security & Offensive Security Researcher
Web & API pentesting · OAuth / OIDC & identity security · source-code review
🌐 Portfolio · 💼 LinkedIn · 🚩 CTFtime · 🛡️ Snyk
I break authentication systems used by millions, then help ship the fixes. My day job is authorized web and API pentesting as a VAPT engineer. The rest of the time I audit open-source auth frameworks and report what I find.
Most of my bugs are the kind a scanner walks straight past: OAuth/OIDC flaws, auth bypasses, broken access control, business-logic abuse. I find them by reading the code and proving them with a working PoC, then writing the fix up the way a developer actually wants to read it.
| Target | Issue | Severity | Reference |
|---|---|---|---|
| better-auth | OAuth refresh-token replay, missing client auth on the refresh grant | Critical · CVSS 9.1 | CVE-2026-53512 · GHSA-pw9m-5jxm-xr6h |
| better-auth | OIDC alg=none accepted + silent PKCE downgrade |
High · CVSS 8.7 | GHSA-9h47-pqcx-hjr4 |
| n8n (190K★, 100M+ Docker pulls) | OAuth authorization bypass, missing state-param ownership check | Medium | CVE-2026-33720 |
| oauth2-server (Node.js) | OAuth2 library flaw, found by manual review | Medium · CVSS 5.4 | SNYK-JS-OAUTH2SERVER-3009137 |
| SAP | Validated server-side finding via source review | recognized | SAP Security Hall of Fame, May 2026 |
| Twilio (NYSE) | Validated finding | recognized | via HackerOne |
Both better-auth findings and the n8n bug are in the same class of work: cross-protocol OAuth/OIDC identity flaws found by reading source, not scanning. On top of the public CVEs, I've got 25+ validated vulnerabilities across public and private bug-bounty programs and invites to 15+ private programs on Bugcrowd.
web & api pentesting · oauth / oidc & identity · source-code review · devsecops (sast/sca in ci) · ai/llm app security · credential-exposure threat intel
Tooling: Burp Suite (Autorize, Auth Analyzer, JWT Editor, Turbo Intruder), Semgrep, CodeQL, Nuclei, Frida, testssl.sh · Python · Go · Node/TS · Docker · GitHub Actions
🥇 #1-ranked CTF team in Pakistan (Schrödinger Bears, CTFtime) · Black Hat MEA finalist · 1st at AirTech & National CyberMuhafiz 2025 · OSCP in progress
Available for security engagements. Reach me through my portfolio or LinkedIn.