Skip to content
View Sy2n0's full-sized avatar
⭐
Happy Hacking
⭐
Happy Hacking

Organizations

@HUB-EDUCATION

Block or report Sy2n0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Sy2n0/README.md

CVEs Hall-of-Fame

About Me

  • Security Researcher / CTF Player @W4llz

Awards

Year Name Award
2026 Jiyong MSRC - Special Mentions
2026 Jiyong NASA VDP (Vulnerability Disclosure Program) - Hall of Fame
2026 W4llz SekaiCTF 2026 2nd
2025 Jiyong Google Cloud VRP (Vulnerability Reward Program) - Honorable Mention

CVEs

CVE-2026-81379 β€” VS Code Marketplace Policy Bypass via URL Canonicalization

Target

  • microsoft/vscode

Summary

  • VS Code incorrectly derives the enterprise-policy identity of a GitHub Agent Plugin marketplace before fully canonicalizing its repository URL.
  • An attacker can craft a repository path containing traversal components (../) so that VS Code validates it as an allowlisted marketplace while Git resolves the same URL to an attacker-controlled repository.
  • This discrepancy allows an unauthorized marketplace to bypass chat.plugins.strictMarketplaces, install an attacker-controlled Agent Plugin, and execute its configured hooks during normal chat interactions.
  • The vulnerability is a security feature bypass that can lead to remote code execution (CWE-180: Validate Before Canonicalize).

References

CVE-2026-58043 β€” Permission Model Filesystem Allowlist Bypass in Node.js

Target

  • nodejs/node

Summary

  • Improper enforcement in the Node.js Permission Model that can over-grant filesystem access across radix-tree prefix boundaries.
  • Under --permission, an attacker granted access to one path could abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
  • Affected: Node.js main, 22.x, 24.x, 26.x.

References

CVE-2026-15921 β€” LTS Alias Path Traversal in nvm

Target

  • nvm-sh/nvm

Summary

  • Path traversal vulnerability caused by insufficient validation of mirror-supplied LTS codenames.
  • A malicious or compromised Node.js mirror could write outside $NVM_DIR/alias/lts and overwrite shell startup files such as ~/.bashrc, ~/.zshrc, or ~/.profile, potentially leading to command execution when the shell starts.

References

CVE-2026-48718 β€” Firebird

Status

  • Coordinated disclosure (technical details will be published after the embargo).
CVE-2026-1665 β€” Command Injection in nvm

Target

  • nvm-sh/nvm

Summary

  • Command injection caused by insufficient validation of environment variables during wget invocation.

References

CVE-2025-69262 β€” Command Injection in pnpm

Target

  • pnpm/pnpm

Summary

  • Command injection through environment variable substitution, potentially leading to arbitrary code execution in CI/CD and build environments.

References

CVE-2025-14550 β€” Denial of Service in Django

Target

  • django/django

Summary

  • Super-linear processing of repeated HTTP headers in the ASGI request path, enabling a potential denial-of-service attack.

References


Contact

Pinned Loading

  1. I'm an early 🐀 I'm an early 🐀
    1
    🌞 Morning    42 commits  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  24.7%
    2
    πŸŒ† Daytime    66 commits  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  38.8%
    3
    πŸŒƒ Evening    46 commits  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‹β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  27.1%
    4
    πŸŒ™ Night      16 commits  β–ˆβ–‰β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘   9.4%
  2. game box game box
    1
    game box
  3. Sy2n0 Sy2n0 Public

  4. nasa/cFS nasa/cFS Public

    The Core Flight System (cFS)

    C 1.5k 392