moizxsec

// vulnerability research · appsec · offensive engineering

Abdul Moiz

Offensive security engineer. I find ways to break web applications, identity providers, cloud platforms, and the chains that hold them together. Then I help fix them.

Currently shipping AI-assisted application security at a HIPAA / SOC 2 healthcare platform. On the side, I disclose vulnerabilities in open-source software under coordinated disclosure.

Advisories
5
CVE IDs
4
Writeups
12
Critical / High
6 / 6

CVEs & advisories

5
view all

Vulnerabilities I found and reported to maintainers. Each row is a full writeup: root cause, proof of concept, fix, and the disclosure timeline.

ID pendingdecompress-zip: Zip Slip Arbitrary File Write via a Sibling-Prefix BypassAffecteddecompress-zip ≤ 0.3.3 (no fix available)npm · bower/decompress-zipSeverity High 8.1 WeaknessCWE-22Status Public Date
CVE-2026-59972GHSA-2756-j7rr-9464unzipper: Zip Slip Arbitrary File Write via a Sibling-Prefix Path BypassAffectedunzipper ≤ 0.12.4npm · ZJONSSON/node-unzipperfixed in 0.12.5Severity High 8.1 WeaknessCWE-22Status Patched Date
CVE-2026-55091GHSA-hp36-v28f-w3r4flat-to-nested: Prototype Pollution via a __proto__ Parent KeyAffectedflat-to-nested ≤ 1.1.1npm · joaonuno/flat-to-nested-jsfixed in 1.1.2Severity High 7.5 WeaknessCWE-1321Status Patched Date
CVE-2026-54283GHSA-82w8-qh3p-5jfqStarlette: Form-Parser Limits Silently Ignored for URL-Encoded BodiesAffectedstarlette >= 0.4.1, < 1.3.1PyPI · encode/starlettefixed in 1.3.1Severity High 7.5 WeaknessCWE-770Status Patched Date
CVE-2026-63358FileGator v7.14.0: Privilege Escalation via Unvalidated chmod EndpointAffectedFileGator < 7.14.2Packagist · filegator/filegatorfixed in 7.14.2Severity High 7.3 WeaknessCWE-732Status Patched Date

Research & writeups

7
view all

Focus

about
Web · API
OWASP, NIST 800-115, PTES, OSSTMM
Identity
Active Directory, Entra ID, SAML, OAuth 2.0, OIDC, JWT
Cloud
AWS WAF, Azure, Firebase, Power Platform misconfiguration
AI / agents
Prompt-injection defence, dual-LLM cascades, automated CVE triage
Coordinated disclosure

90-day window from vendor acknowledgement. If you maintain something I've written about and want to talk, email is the most reliable channel.

muezzism@gmail.com