Skip to content
View EaEa0001's full-sized avatar

Block or report EaEa0001

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
EaEa0001/README.md

Typing SVG

┌──(root㉿EaEa0001)-[~]
└─# whoami

Ea001 — Independent Security Researcher
Focus: Web/AppSec · Vulnerability Discovery & Responsible Disclosure
       AI/LLM Application Security (Agents, RAG, MCP)
       Security Tooling & Automation

┌──(root㉿EaEa0001)-[~]
└─# ls -1 ~/disclosures | wc -l
10

~/disclosures — CVE & Advisory Tracker

# Target Vulnerability Reference Notes
1 Dify SSRF CVE-2026-28504 Server-side request forgery
2 SiYuan Note Sensitive-path read bypass CVE-2026-25992 Case-insensitive filesystem bypass of path interception
3 Remotion RCE (Windows) CVE-2026-30120 Direct remote code execution
4 Remotion Arbitrary file write CVE-2026-30121 Via file upload
5 Flowise Broken access control CVE-2026-70471 Privilege escalation, potential RCE
6 Windows Notepad RCE CVE-2026-20841 Assisted in follow-up bypass discovery
7 OpenClaw Broken access control CVE-2026-41298
8 RAGFlow RCE CVE-2026-35513 Remote code execution
9 Zammad Minor security issue CVE-2026-34720 Low-impact finding
10 Cloudreve OAuth2 bypass CVE-2026-54560 OAuth2 flow bypass

~/arsenal

Python Java TypeScript Shell Docker Linux Burp Suite Kali


~/stats

Profile Details GitHub Stats Repos per Language GitHub Streak

┌──(root㉿EaEa0001)-[~]
└─# echo $MOTTO
"Hack the planet — responsibly."
Profile views

Popular repositories Loading

  1. code-agent-scan code-agent-scan Public

    Python 2

  2. ApertureStatsTool ApertureStatsTool Public

    Python 1

  3. servu-cve-2026-28318-poc servu-cve-2026-28318-poc Public

    SolarWinds Serv-U CVE-2026-28318: unauthenticated Content-Encoding: deflate crash. Root-cause analysis (invalid free of an interior pointer -> heap corruption) + DoS-only PoC. Fixed in 15.5.4 Hotfi…

    Python 1

  4. PeiQi-WIKI-POC PeiQi-WIKI-POC Public

    Forked from MornS0/PeiQi-WIKI-POC

    鹿不在侧,鲸不予游🐋

    HTML

  5. cf cf Public

    Forked from Phuong39/cf

    Cloud Exploitation Framework 云环境利用框架,方便安全人员在获得 AK 的后续工作

    Go

  6. EaEa0001 EaEa0001 Public