moizxsec

// disclosure record

CVEs & advisories

Every vulnerability I have reported to a maintainer, with its public identifier where one has been assigned. Rows link to the full writeup: root cause, proof of concept, fix, and timeline. The table is generated from each writeup's metadata, so it stays in step with the research.

Advisories
5
CVE IDs
4
Patched
4
Years active
2026
ID pendingdecompress-zip: Zip Slip Arbitrary File Write via a Sibling-Prefix BypassAffecteddecompress-zip ≤ 0.3.3 (no fix available)npm · bower/decompress-zipSeverity High 8.1 WeaknessCWE-22Status Public Date
CVE-2026-59972GHSA-2756-j7rr-9464unzipper: Zip Slip Arbitrary File Write via a Sibling-Prefix Path BypassAffectedunzipper ≤ 0.12.4npm · ZJONSSON/node-unzipperfixed in 0.12.5Severity High 8.1 WeaknessCWE-22Status Patched Date
CVE-2026-55091GHSA-hp36-v28f-w3r4flat-to-nested: Prototype Pollution via a __proto__ Parent KeyAffectedflat-to-nested ≤ 1.1.1npm · joaonuno/flat-to-nested-jsfixed in 1.1.2Severity High 7.5 WeaknessCWE-1321Status Patched Date
CVE-2026-54283GHSA-82w8-qh3p-5jfqStarlette: Form-Parser Limits Silently Ignored for URL-Encoded BodiesAffectedstarlette >= 0.4.1, < 1.3.1PyPI · encode/starlettefixed in 1.3.1Severity High 7.5 WeaknessCWE-770Status Patched Date
CVE-2026-63358FileGator v7.14.0: Privilege Escalation via Unvalidated chmod EndpointAffectedFileGator < 7.14.2Packagist · filegator/filegatorfixed in 7.14.2Severity High 7.3 WeaknessCWE-732Status Patched Date

Status vocabulary

Reported
Sent to the maintainer; awaiting acknowledgement or fix.
Coordinated
Acknowledged; fix and identifier in progress under embargo.
Patched
A fixed release is available.
Public
Details published; no vendor fix applies (class or research).

Disclosure policy

90-day coordinated disclosure from the date a vendor acknowledges receipt. If a vendor is unresponsive after reasonable follow-up, or active exploitation is observed, I may publish sooner. Full policy.