// vulnerability research · appsec · offensive engineering
Abdul Moiz
Offensive security engineer. I find ways to break web applications, identity providers, cloud platforms, and the chains that hold them together. Then I help fix them.
Currently shipping AI-assisted application security at a HIPAA / SOC 2 healthcare platform. On the side, I disclose vulnerabilities in open-source software under coordinated disclosure.
- Advisories
- 5
- CVE IDs
- 4
- Writeups
- 12
- Critical / High
- 6 / 6
CVEs & advisories
5Vulnerabilities I found and reported to maintainers. Each row is a full writeup: root cause, proof of concept, fix, and the disclosure timeline.
| Identifier | Affected | Severity | Weakness | Status | Date |
|---|---|---|---|---|---|
| ID pendingdecompress-zip: Zip Slip Arbitrary File Write via a Sibling-Prefix Bypass | Affecteddecompress-zip ≤ 0.3.3 (no fix available)npm · bower/decompress-zip | Severity High 8.1 | WeaknessCWE-22 | Status Public | Date |
| CVE-2026-59972GHSA-2756-j7rr-9464unzipper: Zip Slip Arbitrary File Write via a Sibling-Prefix Path Bypass | Affectedunzipper ≤ 0.12.4npm · ZJONSSON/node-unzipperfixed in 0.12.5 | Severity High 8.1 | WeaknessCWE-22 | Status Patched | Date |
| CVE-2026-55091GHSA-hp36-v28f-w3r4flat-to-nested: Prototype Pollution via a __proto__ Parent Key | Affectedflat-to-nested ≤ 1.1.1npm · joaonuno/flat-to-nested-jsfixed in 1.1.2 | Severity High 7.5 | WeaknessCWE-1321 | Status Patched | Date |
| CVE-2026-54283GHSA-82w8-qh3p-5jfqStarlette: Form-Parser Limits Silently Ignored for URL-Encoded Bodies | Affectedstarlette >= 0.4.1, < 1.3.1PyPI · encode/starlettefixed in 1.3.1 | Severity High 7.5 | WeaknessCWE-770 | Status Patched | Date |
| CVE-2026-63358FileGator v7.14.0: Privilege Escalation via Unvalidated chmod Endpoint | AffectedFileGator < 7.14.2Packagist · filegator/filegatorfixed in 7.14.2 | Severity High 7.3 | WeaknessCWE-732 | Status Patched | Date |
Research & writeups
7Focus
90-day window from vendor acknowledgement. If you maintain something I've written about and want to talk, email is the most reliable channel.