Skip to content
View supperhellokitty20's full-sized avatar
🗻
The root of suffering is attachment.
🗻
The root of suffering is attachment.

Block or report supperhellokitty20

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
supperhellokitty20/README.md

Hi, I'm qtduck 👋

System Administrator · Security Researcher · CTF Player

Published CVEs Security Acknowledgements CTF Team

I build and operate systems, investigate security flaws, and enjoy turning curious observations into responsible disclosures.

Website · Security blog · HackerOne · GitHub

🛡️ Published Security Research

The following vulnerabilities were responsibly reported and publicly disclosed. GitHub Security Advisory entries credit @supperhellokitty20 as a reporter where shown; other reports include vendor or HackerOne attribution.

CVE Project Finding Severity Advisory / reference
CVE-2026-55420 Discourse Remote code execution via PDF uploads High GHSA-7wq5-jgww-5rw3
CVE-2026-39251 tmux Heap overflow in sixel_print_add affecting versions 3.4–3.6a Unrated Fix commit
CVE-2026-54301 n8n Same-Origin XSS in Respond to Webhook Node High GHSA-v733-mwr6-fgcm
CVE-2026-50130 Pi-hole Local privilege escalation from pihole to root via logrotate High GHSA-h8w9-qx2v-wrww
CVE-2026-49246 Jellyfin Potential MKV attachment filename path traversal to RCE Low GHSA-f47c-m7gr-q92j

CVE-2026-55420 was reported to Discourse through HackerOne by fizzi. The public GitHub advisory does not list reporter credits.

🔎 Security Acknowledgements

Publicly fixed security reports that do not have a CVE assignment.

Project Finding Fixed in Public acknowledgement Fix
LimeSurvey Issue #20495: Unrestricted getConfig() access in the Twig sandbox 6.17.4 Release notes PR #4917 · Commit

LimeSurvey publicly thanked supperhellokitty20 for reporting this issue.

🔐 Responsible Disclosure

I follow coordinated disclosure practices and publish research details only after the affected project has released its advisory or fix.

Break things thoughtfully. Report them responsibly. Make software safer.

Pinned Loading

  1. homepage homepage Public

    Next js homepage

    TypeScript

  2. build-your-own-x build-your-own-x Public

    Forked from codecrafters-io/build-your-own-x

    🤓 Build your own (insert technology here)

    2

  3. ctf-katana ctf-katana Public

    Forked from JohnHammond/ctf-katana

    This repository aims to hold suggestions (and hopefully/eventually code) for CTF challenges. The "project" is nicknamed Katana.

    1

  4. deepmind-research deepmind-research Public

    Forked from google-deepmind/deepmind-research

    This repository contains implementations and illustrative code to accompany DeepMind publications

    Jupyter Notebook 1

  5. Discord-Werewolf Discord-Werewolf Public

    Forked from belguawhale/Discord-Werewolf

    A discord bot that runs a game of Werewolf. The official Discord Werewolf server is at https://discord.gg/V2E8Vzc

    Python 1

  6. LinEnum LinEnum Public

    Forked from rebootuser/LinEnum

    Scripted Local Linux Enumeration & Privilege Escalation Checks

    Shell 1