v4nsh0x
// v4nsh0x

VANSH
SAXENA

Security researcher focused on breaking web applications, finding vulnerabilities, and understanding how systems fail. My work spans web and API security, penetration testing, bug bounty hunting, memory corruption, and exploit development.

DISCIPLINE Web Security / Pentesting
STATUSActively hunting
DISCLOSED4 CVEs
DESCEND
Photon Sphere

Achievements

Light can orbit here before it escapes — r = 1.5 Rₛ

The things that made it out into the open

2025
Multiple Security Hall of Fame Recognitions
Recognized by organizations including NASA, Lenovo, and others
2025
Featured in National Media
Security research featured across national newspapers and television channels
Accretion Disk

Research

Matter under active analysis, glowing at temperatures that scale with severity

Published writeups are open — click through to read the full disclosure. Everything else is still under embargo.

Ergosphere

Bug Bounty

Nothing sits still here, but you can still extract energy and get out

A selection from my bug bounty work. There is more beyond this ledger, but I'm too lazy to write everything up.

ProgramClassSeverityStatus
Mercedes-Benz Account Takeover Critical Resolved
X Payment Bypass Critical Resolved
NASA Stored XSS High Resolved
Perplexity Prompt Injection High Resolved
Claude Code Prompt Injection High Resolved
Google Gemini Remote Code Execution (RCE) Critical Triaged
Event Horizon

Areas of Interest

Past this point, everything gets interesting

Curious about how things work. More curious about how they fail.

Web Application Security API Security Authentication & Authorization Bug Bounty Hunting Penetration Testing OSINT Business Logic Flaws Memory Corruption Exploit Development Reverse Engineering Fuzzing
Singularity

Get in touch

r = 0 — everything converges here
PGP FINGERPRINT FD79 EF99 9B39 9F4F 9C83 106A 1CB0 7058 F90C C613