Student Security Portfolio

Web Pentesting, Agent Security, and Vulnerability Research.

Cybersecurity student focused on web exploitation, access-control flaws, agent offense and defense, and responsible disclosure. This preview intentionally redacts target details, payloads, endpoints, and personal identifiers.

FocusAgent Security
Publications2 arXiv Preprints
Public Records15 Advisory Credits
01

Profile

Security work grounded in real systems, careful validation, and responsible public reporting.

I am a security-focused computing student with hands-on work across university systems, especially identity flows, student-service platforms, and legacy web applications.

The public version should emphasize classes of findings and reporting discipline rather than raw exploit detail. That makes the page stronger and safer at the same time.

Current direction: web pentesting, agent offense and defense, vulnerability research, traditional visual algorithms such as KCF, introductory open-source research, and turning private reports into clean public case studies.

My work spans hands-on vulnerability research and research on the reliability and security of LLM agents operating through real environments.

Collaborators Liyi Zhou
Ziyue Wang

I collaborate with Dr. Liyi Zhou and his PhD student, Ziyue Wang, on the security and reliability of LLM agents. Our 2026 work includes EnvTrustBench and EvoHunt.

02

Publications

03

Projects

Hash ScanTeam project · September 2026

Co-developed with teammates, Hash Scan is a HashKey Chain transaction explorer built around historical transaction data, with Etherscan-inspired action labeling and transaction analysis. Public code repository ↗

04

Vulnerability Reports

Public and private vulnerability reporting.

CVE RecordsEvoHunt

Contributed to a team research effort resulting in 40 CVEs, with individual credits in 15 public advisories. My contributions span research, validation, and responsible disclosure, with Finder and Reporter roles recorded by GitHub. Assigned records awaiting publication remain masked below. View all public advisory credits ↗

Public advisory credit · ReporterHigh · sigstore

CVE-2026-48815

Certificate OID verification constraints silently dropped.

Public advisory credit · ReporterModerate · @sigstore/verify

CVE-2026-48816

Insufficient verification of transparency-log timestamp authenticity.

Public advisory credit · ReporterModerate · @sigstore/core

CVE-2026-48758

DSSE payloadType type-binding failure.

Public advisory credit · ReporterModerate · http-proxy-middleware

CVE-2026-55602

Host-header-driven backend routing bypass.

Public advisory credit · ReporterHigh · electron-builder

CVE-2026-54673

Cross-origin updater redirects can expose credential-bearing headers.

Public advisory credit · ReporterModerate · webpack-dev-server

CVE-2026-14631

Malformed Host or Origin headers can terminate the development server.

Public advisory credit · FinderLow · joi

CVE-2026-84367

Template-based key renaming can alter the validated object's prototype.

Public advisory credit · ReporterModerate · JupyterHub

CVE-2026-54338

Unbounded username logging can exhaust resources during failed logins.

Public advisory credit · FinderModerate · djangoCMS

CVE-2026-54625

Page caching ignores plugin-declared Vary headers, risking disclosure and cache poisoning.

Public advisory credit · FinderHigh · djangoCMS

CVE-2026-54623

Cyclic plugin reparenting can cause denial of service.

Public advisory credit · FinderModerate · djangoCMS

CVE-2026-54624

Structure access bypasses page-view permissions.

Public advisory credit · FinderModerate · djangoCMS

CVE-2026-54622

Clipboard copying can disclose unauthorized plugin content.

Public advisory credit · ReporterLow · Mermaid

CVE-2026-71438

Configuration APIs can allow prototype pollution.

Public advisory credit · ReporterHigh · Socket.IO/socket.io-parser

CVE-2026-69185

Zero-attachment packets can trigger memory exhaustion.

Public advisory credit · FinderHigh · undici

CVE-2026-9675

WebSocket fragment-limit bypass can exhaust memory.

CVE-2026-6***

CVE-2026-14***

CVE-2026-58***

Masked records will be completed after coordinated public disclosure.
Private ReportsCampus Systems

Nine responsibly reported findings across SSO, library, leave-management, OA, and other campus web systems.

Identity and Verification FlowsAuth logic

Reported weaknesses in account and verification flows, including abusive verification paths and exposure in account-related records.

Student-Service Access ControlIDOR / authz

Reported access-control issues affecting leave-management and booking systems, where personal or workflow data could be returned across users.

Legacy Campus Web AppsXSS / exposure

Documented XSS-class issues, guest-access mistakes, and file-exposure problems in older campus platforms.

Recognition

An institutional certificate recognizes vulnerability reporting and remediation support. Technical details, identifiers, and reproduction steps remain private.

05

Education

EducationAcademic Study
University of SydneyCurrent

Master of Computer Science.

Dalian Maritime University2020-2024

Electronic Information Engineering student.

Campus ExperienceCompetitions & Leadership
Ethereum Hackathon @ SydneySeptember 2026

3rd Place, EAG Track — team award for Hash Scan.

Nexus CTF2026

7th place at the University of Sydney.

HackMac2026

4th place at Macquarie University.

Qihang Computer Society2020-2024

Head of the Network Security Department at Dalian Maritime University.