VANSH
SAXENA
Security researcher focused on breaking web applications, finding vulnerabilities, and understanding how systems fail. My work spans web and API security, penetration testing, bug bounty hunting, memory corruption, and exploit development.
Achievements
The things that made it out into the open
Research
Published writeups are open — click through to read the full disclosure. Everything else is still under embargo.
Unauthenticated packets can advance the SRTP AES-GCM replay window and rollover counter, weakening replay protection.
An attacker-controlled attachment MIME type can be used to achieve stored cross-site scripting in Hasty-Paste.
Bug Bounty
A selection from my bug bounty work. There is more beyond this ledger, but I'm too lazy to write everything up.
| Program | Class | Severity | Status |
|---|---|---|---|
| Mercedes-Benz | Account Takeover | Critical | Resolved |
| X | Payment Bypass | Critical | Resolved |
| NASA | Stored XSS | High | Resolved |
| Perplexity | Prompt Injection | High | Resolved |
| Claude Code | Prompt Injection | High | Resolved |
| Google Gemini | Remote Code Execution (RCE) | Critical | Triaged |
Areas of Interest
Curious about how things work. More curious about how they fail.