Skip to content
View kuranikaran's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report kuranikaran

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kuranikaran/README.md

Karan Kurani

Security Researcher · Offensive Security · Vulnerability Disclosure

Portfolio LinkedIn

Typing SVG

CVEs Published          CVE-2026-32230 | +2 CVE in Progress
Organizations           14 (Apple · Meta · NASA · OpenAI · JPMC · Infosys …)
Certs                   CRTA · ISC² CC · NCPT · OCI Architect
TryHackMe               Top 1% | Seven Time League Winner #1
NCL                     Top 7% National · #1 at Pace
PortSwigger             100+ Labs

CVEs & Credited Findings

Severity Target Finding ID
🔴 Critical React / Next.js RCE via exposed RSC endpoints on The Economic Times Admin Portal CVE-2025-55182
🟡 Medium Uptime Kuma ★83K Missing authorization on monitor pings CVE-2026-32230
✅ Fixed Pretix Log injection via request_id_header PR #5920
✅ Fixed Pretix OIDC PKCE values logged to stdout Responsible Disclosure
✅ Fixed Metabase ★46K Sharing bypass exposing datasets GHSA-j3qp-7mr8-hr55)
⿻ Duplicate n8n Authorization bypass (IDOR) GHSA-vh2p-7mqh-wwhw
⿻ Duplicate n8n Authenticated SSRF via workflows/from-url GHSA-7rp7-qh7m-h47v
🤝 Credited Directus Enumeration oracle via RBAC filter bypass GHSA-2xcm-7h22-3m66
🏆 Hall of Fame JPMorgan Chase Internal hostnames in prod JS Synack RD #690

Additional disclosures to NASA · OpenAI · Microsoft · Mercedes-Benz · Infosys (CERT-In acknowledged)


Tech

Python Bash C C++ JS PowerShell SQL

Burp Metasploit Nmap Wireshark Ghidra IDA Semgrep ASan

Kali Docker AWS Wazuh Splunk MITRE ATT&CK


Now

🔬 Fuzzing Fang engine's for memory corruption bugs
🔍 Source code auditing high-star open-source projects
⚡  Manual + Multi-LLM workflow 
🏆 OSCP | BSCP Prep 
🏴󠁡󠁦󠁷󠁡󠁲󠁿 Hands'on Offsec | THM | HTB | Portswigger

CRTA ISC² CC NCPT OCI


Pinned Loading

  1. CVSSv3 CVSSv3 Public

    Jupyter Notebook

  2. Leetcode Leetcode Public

    Python

  3. JWT-Attacks JWT-Attacks Public

  4. Offensive-Security-Wireless-Pentester Offensive-Security-Wireless-Pentester Public

    Wireless Security