Security Engineer at Amazon, working in IAM security on bringing agentic AI into identity and access management. Outside that, I hunt unauthenticated remote code execution in the infrastructure that runs large language models: agent frameworks, inference servers, workflow orchestrators, and the serialization formats they trust.
7 CVEs assigned · 12 published advisories · 167 filed across 59 projects
| Advisory | Project | CVSS | Class |
|---|---|---|---|
| CVE-2026-57516 | ray |
Code injection (CWE-94) | |
| CVE-2026-45675 | open-webui |
Privilege escalation (CWE-269) | |
| GHSA-pqxw-g93w-hj9x | trigger.dev |
Improper isolation (CWE-653) | |
| GHSA-jc26-22qp-cgqj | trigger.dev |
Missing authentication (CWE-306) | |
| GHSA-3c52-v5v2-3r56 | budibase |
Server side request forgery (CWE-918) | |
| CVE-2026-59714 | open-webui |
Missing authorization (CWE-862) | |
| GHSA-8p4j-2mm9-rh78 | Tracecat |
Server side request forgery (CWE-918) | |
| CVE-2026-53577 | kestra |
Incorrect authorization (CWE-863) | |
| CVE-2026-63342 | hatchet |
Incorrect authorization (CWE-863) | |
| GHSA-59h8-w5q6-mfmp | trigger.dev |
Missing authentication (CWE-306) | |
| CVE-2026-73301 | @budibase/server |
Missing authorization (CWE-862) | |
| CVE-2026-59715 | open-webui |
Missing authentication (CWE-306) |
Each advisory above links to a full writeup: root cause, the vulnerable code, reproduction steps and the fix. Mirrored at sfwani/advisories.
Table regenerates daily from published advisories credited to me. Verify independently: GitHub Advisory Database.
|
Unauthenticated reachability An auth gated code execution sink is a bug. The same sink reachable before auth is a 10.0. My highest severity findings are reachability failures rather than novel sinks: CWE-306 and CWE-862 standing in front of machinery that was never meant to be public. |
Sandboxes that are not sandboxes Agent frameworks ship "safe" Python evaluators built on AST allowlists. Format string dunder traversal, decorator abuse, and incomplete node denylists walk straight out of most of them. |
|
Deserialization on exposed ports
|
Request forgery into control planes My highest volume class (CWE-918): metadata endpoints, internal schedulers, and cluster APIs one redirect away from a user supplied URL. |
Reports go to maintainers privately, through GitHub Security Advisories or the project's stated security channel, never a public issue tracker. Advisories carry a 90 day disclosure window. Nothing is named, hinted at, or mirrored publicly until the maintainer publishes.
| Placement | Event |
|---|---|
| 1st | AI Village CTF, DEF CON 34 |
| 2nd | Adversary Wars CTF, Adversary Village, DEF CON 34 |
| 1st | Adversary Wars CTF, Adversary Village, DEF CON 33 |
| 1st | SHPE National CTF |
| 1st | Hackabull CTF |
| 1st | Central Florida Tech Grove CTF |
| 1st | Social Engineering Competition, The CARE Lab at Temple University |
| 3rd | SecureTheFuture Research Award, Palo Alto Networks |
| 3rd | NCAE CyberGames, South East Regionals |
Website · Experience · Advisories · LinkedIn

