Every published CVE, security advisory, and paper below is credited to Pavan Nallamothu (handle pavanchow) and mapped to an independent third-party source that names the researcher. These are published vulnerability-research findings credited by the vendor, not bounties.
Full technical write-ups and reproduction scripts live on the technical hub, pavanchow.github.io. CVE-2026-63013 and CVE-2026-63014 are GitHub-CNA-assigned and credited in their advisories; their MITRE/cve.org records have not yet propagated, so the GitHub Security Advisory is cited as the canonical source.
| Contribution | Independent source | Live link |
|---|---|---|
| CVE-2026-43763 — Apple macOS ATS sandbox file-read (co-credited: Pavan Nallamothu, Jared Reyes) | Apple security release | support.apple.com/en-us/128067 |
| CVE-2026-33234 — AutoGPT SSRF via user-controlled SMTP server | GitHub Security Advisory GHSA-4jwj-6mg5-wrwf | github.com/…/GHSA-4jwj-6mg5-wrwf |
| CVE-2026-40585 — blueprintUE non-expiring password-reset tokens | GitHub Security Advisory GHSA-qr65-6vp8-whjf | github.com/…/GHSA-qr65-6vp8-whjf |
| CVE-2026-40586 — blueprintUE missing brute-force protection on login | GitHub Security Advisory GHSA-m6c2-6p3h-8jv2 | github.com/…/GHSA-m6c2-6p3h-8jv2 |
| CVE-2026-40587 — blueprintUE session not invalidated on credential change | GitHub Security Advisory GHSA-gqpq-x62g-p4mg | github.com/…/GHSA-gqpq-x62g-p4mg |
| CVE-2026-40588 — blueprintUE password change without current-password check | GitHub Security Advisory GHSA-73f2-p9jr-m44x | github.com/…/GHSA-73f2-p9jr-m44x |
| CVE-2026-50023 — yt-dlp dangerous file creation | GitHub Security Advisory GHSA-c6mh-fpjc-4pr3 | github.com/advisories/GHSA-c6mh-fpjc-4pr3 |
| CVE-2026-63013 — NSA skills-service privilege escalationMITRE record pending | GitHub Security Advisory GHSA-67x3-r85f-822r | github.com/…/GHSA-67x3-r85f-822r |
| CVE-2026-63014 — NSA skills-service cross-project IDORMITRE record pending | GitHub Security Advisory GHSA-p527-vjfp-c43p | github.com/…/GHSA-p527-vjfp-c43p |
| CVE-2026-63133 — CISA Malcolm inode-exhaustion DoS | GitHub Security Advisory GHSA-c35g-mgc3-95rx | github.com/cisagov/Malcolm/…/GHSA-c35g-mgc3-95rx |
| CVE-2026-63134 — CISA Malcolm archive path traversal | GitHub Security Advisory GHSA-65mm-vgrw-vqx4 | github.com/cisagov/Malcolm/…/GHSA-65mm-vgrw-vqx4 |
| CVE-2026-63177 — CISA Malcolm RBAC / URI-normalization bypass | GitHub Security Advisory GHSA-m5fr-rv3h-xg2r | github.com/cisagov/Malcolm/…/GHSA-m5fr-rv3h-xg2r |
| GHSA-w8gq-4v5x-xrrm — CISA Malcolm unauthenticated script execution via CSRF (kiosk /script_call), no CVE | GitHub Security Advisory | github.com/cisagov/Malcolm/…/GHSA-w8gq-4v5x-xrrm |
| GHSA-86h3-7rf8-8j34 — CISA Malcolm missing server-to-server auth on Hedgehog Sensor Arkime reachback port, no CVE | GitHub Security Advisory | github.com/cisagov/Malcolm/…/GHSA-86h3-7rf8-8j34 |
| Paper — SSRF Beyond HTTP: Egress-Path-Incomplete Guards in AI Agent Platforms | Zenodo, DOI 10.5281/zenodo.22075470 | zenodo.org/records/22075470 |
| Paper — Trusting the Filename: File-Write Attacks from Untrusted Archive and Download Metadata | Zenodo, DOI 10.5281/zenodo.22075439 | zenodo.org/records/22075439 |
| ORCID 0009-0009-1481-6629 — verified researcher record | ORCID | orcid.org/0009-0009-1481-6629 |