Skip to content
View Sy2n0's full-sized avatar
Happy Hacking
Happy Hacking

Organizations

@HUB-EDUCATION

Block or report Sy2n0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Sy2n0/README.md

CVEsHall-of-Fame

About Me

  • Security Researcher / CTF Player @W4llz

Awards

YearNameAward
2026JiyongNASA VDP (Vulnerability Disclosure Program) - Hall of Fame
2026W4llzNO HACK NO CTF 2026 1st
2026W4llzSekaiCTF 2026 2nd
2026W4llzBreak The Syntax CTF 2026 2nd
2025JiyongGoogle Cloud VRP (Vulnerability Reward Program) - Honorable Mention

Hall of Fame


CVEs

CVE-2026-58043 — Permission Model Filesystem Allowlist Bypass in Node.js

Target

  • nodejs/node

Summary

  • Improper enforcement in the Node.js Permission Model that can over-grant filesystem access across radix-tree prefix boundaries.
  • Under --permission, an attacker granted access to one path could abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
  • Affected: Node.js main, 22.x, 24.x, 26.x.

References

CVE-2026-15921 — LTS Alias Path Traversal in nvm

Target

  • nvm-sh/nvm

Summary

  • Path traversal vulnerability caused by insufficient validation of mirror-supplied LTS codenames.
  • A malicious or compromised Node.js mirror could write outside $NVM_DIR/alias/lts and overwrite shell startup files such as ~/.bashrc, ~/.zshrc, or ~/.profile, potentially leading to command execution when the shell starts.

References

CVE-2026-48718 — Firebird

Status

  • Coordinated disclosure (technical details will be published after the embargo).
CVE-2026-1665 — Command Injection in nvm

Target

  • nvm-sh/nvm

Summary

  • Command injection caused by insufficient validation of environment variables during wget invocation.

References

CVE-2025-69262 — Command Injection in pnpm

Target

  • pnpm/pnpm

Summary

  • Command injection through environment variable substitution, potentially leading to arbitrary code execution in CI/CD and build environments.

References

CVE-2025-14550 — Denial of Service in Django

Target

  • django/django

Summary

  • Super-linear processing of repeated HTTP headers in the ASGI request path, enabling a potential denial-of-service attack.

References


Contact

Pinned Loading

  1. I'm an early 🐤I'm an early 🐤
    1
    🌞 Morning 42 commits █████▏░░░░░░░░░░░░░░░ 24.7%
    2
    🌆 Daytime 66 commits ████████▏░░░░░░░░░░░░ 38.8%
    3
    🌃 Evening 46 commits █████▋░░░░░░░░░░░░░░░ 27.1%
    4
    🌙 Night 16 commits █▉░░░░░░░░░░░░░░░░░░░ 9.4%
  2. game boxgame box
    1
    game box
  3. Sy2n0Sy2n0Public

  4. nasa/cFSnasa/cFSPublic

    The Core Flight System (cFS)

    C 1.5k 383