Skip to content
View 0xBassia's full-sized avatar

Block or report 0xBassia

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xBassia/README.md

> whoami

┌──(root㉿0xbassia)-[~]
└─# cat profile.txt

[+] Name........: Mohamed Bassia
[+] Role........: Security Researcher / Vulnerability Hunter
[+] Specialties.: Source-code auditing, 0-day discovery, web exploitation
[+] Bug classes.: Prototype pollution, SSRF, IDOR, CSRF, auth bypass
[+] Credits.....: 10 published CVEs (6 GitHub-reviewed + 4 WPScan)
[+] Status......: Reading code others trust, finding what they missed

> arsenal --list

Source-Code Auditing & SAST

CodeQL Semgrep CodeChecker Manual Review

Vulnerability Research & Exploitation

Burp Suite pwntools Ghidra Frida

Fuzzing & Supply-Chain

AFL++ libFuzzer OSV Dependency Audit

Languages

Python JavaScript TypeScript Go C Bash

> CVEs --published

10 published CVEs  ·  unauth RCE, SSRF, prototype pollution, access control  ·  npm & WordPress

CVE Package / Plugin Severity Vulnerability Class
CVE-2026-47378 nocodb 🟠 Medium Hidden column exposure in public shared views (broken access control)
CVE-2026-46510 form-data-objectizer 🔴 High 8.2 Prototype pollution (bracket-notation keys)
CVE-2026-46509 @ranfdev/deepobj 🔴 High 8.2 Prototype pollution
CVE-2026-45325 @tmlmobilidade/utils 🔴 High 8.2 Prototype pollution (setValueAtPath)
CVE-2026-45302 parse-nested-form-data 🔴 High 8.2 Prototype pollution (__proto__ in form fields)
CVE-2026-44483 @rvf/set-get 🔴 High 8.2 Prototype pollution (via @rvf/core preprocessFormData)
CVE-2026-9815 MagicForm (<= 0.1.3) 🔴 High Unauthenticated arbitrary file upload to RCE
CVE-2026-12516 Fediverse Embeds (< 1.5.8) 🔴 High 7.5 Unauthenticated SSRF via media proxy (full read + open proxy)
CVE-2026-12517 Fediverse Embeds (< 1.5.8) 🟠 Medium 5.3 Unauthenticated SSRF via site-info endpoint
CVE-2026-9067 Schema & Structured Data for WP & AMP (< 1.60) 🔴 High Unauthenticated arbitrary media upload

6 npm CVEs credited via the GitHub Advisory Database · 4 WordPress CVEs disclosed through WPScan

> stats --github

Profile details

Streak

Activity graph

> achievements --unlock

🛡️ 10× Published CVEs · 🦈 Pull Shark ×2 · ⚡ Quickdraw · 👥 Pair Extraordinaire · 🧊 Arctic Code Vault Contributor

> contact --secure





root@0xbassia:~# echo "Hack the planet, responsibly."

Pinned Loading

  1. security-research security-research Public

    Vulnerability disclosures and root-cause analysis. 10 published CVEs across npm and WordPress: prototype pollution, broken access control, unauthenticated upload to RCE, and SSRF.