I build and operate systems, investigate security flaws, and enjoy turning curious observations into responsible disclosures.
Website · Security blog · HackerOne · GitHub
The following vulnerabilities were responsibly reported and publicly disclosed. GitHub Security Advisory entries credit
@supperhellokitty20 as a reporter where shown; other reports include vendor or HackerOne attribution.
| CVE | Project | Finding | Severity | Advisory / reference |
|---|---|---|---|---|
| CVE-2026-55420 | Discourse | Remote code execution via PDF uploads | High | GHSA-7wq5-jgww-5rw3 |
| CVE-2026-39251 | tmux | Heap overflow in sixel_print_add affecting versions 3.4–3.6a |
Unrated | Fix commit |
| CVE-2026-54301 | n8n | Same-Origin XSS in Respond to Webhook Node | High | GHSA-v733-mwr6-fgcm |
| CVE-2026-50130 | Pi-hole | Local privilege escalation from pihole to root via logrotate |
High | GHSA-h8w9-qx2v-wrww |
| CVE-2026-49246 | Jellyfin | Potential MKV attachment filename path traversal to RCE | Low | GHSA-f47c-m7gr-q92j |
CVE-2026-55420 was reported to Discourse through HackerOne by
fizzi. The public GitHub advisory does not list reporter credits.
Publicly fixed security reports that do not have a CVE assignment.
| Project | Finding | Fixed in | Public acknowledgement | Fix |
|---|---|---|---|---|
| LimeSurvey | Issue #20495: Unrestricted getConfig() access in the Twig sandbox |
6.17.4 | Release notes | PR #4917 · Commit |
LimeSurvey publicly thanked
supperhellokitty20for reporting this issue.
I follow coordinated disclosure practices and publish research details only after the affected project has released its advisory or fix.
Break things thoughtfully. Report them responsibly. Make software safer.


