Pavan Nallamothu / Verification & Receipts

Verification & Receipts

Every published CVE, security advisory, and paper below is credited to Pavan Nallamothu (handle pavanchow) and mapped to an independent third-party source that names the researcher. These are published vulnerability-research findings credited by the vendor, not bounties.

Full technical write-ups and reproduction scripts live on the technical hub, pavanchow.github.io. CVE-2026-63013 and CVE-2026-63014 are GitHub-CNA-assigned and credited in their advisories; their MITRE/cve.org records have not yet propagated, so the GitHub Security Advisory is cited as the canonical source.

ContributionIndependent sourceLive link
CVE-2026-43763 — Apple macOS ATS sandbox file-read (co-credited: Pavan Nallamothu, Jared Reyes)Apple security releasesupport.apple.com/en-us/128067
CVE-2026-33234 — AutoGPT SSRF via user-controlled SMTP serverGitHub Security Advisory GHSA-4jwj-6mg5-wrwfgithub.com/…/GHSA-4jwj-6mg5-wrwf
CVE-2026-40585 — blueprintUE non-expiring password-reset tokensGitHub Security Advisory GHSA-qr65-6vp8-whjfgithub.com/…/GHSA-qr65-6vp8-whjf
CVE-2026-40586 — blueprintUE missing brute-force protection on loginGitHub Security Advisory GHSA-m6c2-6p3h-8jv2github.com/…/GHSA-m6c2-6p3h-8jv2
CVE-2026-40587 — blueprintUE session not invalidated on credential changeGitHub Security Advisory GHSA-gqpq-x62g-p4mggithub.com/…/GHSA-gqpq-x62g-p4mg
CVE-2026-40588 — blueprintUE password change without current-password checkGitHub Security Advisory GHSA-73f2-p9jr-m44xgithub.com/…/GHSA-73f2-p9jr-m44x
CVE-2026-50023 — yt-dlp dangerous file creationGitHub Security Advisory GHSA-c6mh-fpjc-4pr3github.com/advisories/GHSA-c6mh-fpjc-4pr3
CVE-2026-63013 — NSA skills-service privilege escalationMITRE record pendingGitHub Security Advisory GHSA-67x3-r85f-822rgithub.com/…/GHSA-67x3-r85f-822r
CVE-2026-63014 — NSA skills-service cross-project IDORMITRE record pendingGitHub Security Advisory GHSA-p527-vjfp-c43pgithub.com/…/GHSA-p527-vjfp-c43p
CVE-2026-63133 — CISA Malcolm inode-exhaustion DoSGitHub Security Advisory GHSA-c35g-mgc3-95rxgithub.com/cisagov/Malcolm/…/GHSA-c35g-mgc3-95rx
CVE-2026-63134 — CISA Malcolm archive path traversalGitHub Security Advisory GHSA-65mm-vgrw-vqx4github.com/cisagov/Malcolm/…/GHSA-65mm-vgrw-vqx4
CVE-2026-63177 — CISA Malcolm RBAC / URI-normalization bypassGitHub Security Advisory GHSA-m5fr-rv3h-xg2rgithub.com/cisagov/Malcolm/…/GHSA-m5fr-rv3h-xg2r
GHSA-w8gq-4v5x-xrrm — CISA Malcolm unauthenticated script execution via CSRF (kiosk /script_call), no CVEGitHub Security Advisorygithub.com/cisagov/Malcolm/…/GHSA-w8gq-4v5x-xrrm
GHSA-86h3-7rf8-8j34 — CISA Malcolm missing server-to-server auth on Hedgehog Sensor Arkime reachback port, no CVEGitHub Security Advisorygithub.com/cisagov/Malcolm/…/GHSA-86h3-7rf8-8j34
Paper — SSRF Beyond HTTP: Egress-Path-Incomplete Guards in AI Agent PlatformsZenodo, DOI 10.5281/zenodo.22075470zenodo.org/records/22075470
Paper — Trusting the Filename: File-Write Attacks from Untrusted Archive and Download MetadataZenodo, DOI 10.5281/zenodo.22075439zenodo.org/records/22075439
ORCID 0009-0009-1481-6629 — verified researcher recordORCIDorcid.org/0009-0009-1481-6629