Skip to content
View caveeroo's full-sized avatar
🎯
🎯

Organizations

@B64CTF

Block or report caveeroo

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
caveeroo/README.md

Jaime Cavero Sánchez

Application security / offensive research

Security research, secure development, and vulnerability analysis.

caveeroo.dev · Madrid, Spain

Public disclosure index

12 publicly verified vulnerability records · 7 affected projects

Product Findings Area Research Records
Apktool 1 CVE Path handling Read CVE-2026-39973
Ghidra 3 GHSAs Class loading / resource bounds / paths Read GHSA-r625-mph7-wf6j · GHSA-hrpw-vjfw-gq5r · GHSA-42gp-j98c-2297
Jackson Databind 1 CVE Type validation Read CVE-2026-54512
Joomla 1 CVE CORS validation CVE-2026-71573
Metasploit Framework 1 CVE Authentication / fail-open CVE-2026-16895
Project Oak 1 GHSA ELF loading / attestation GHSA-ffp2-6m26-mg2c
Wireshark 4 CVEs Parsing / memory safety / DoS Read CVE-2026-7375 · CVE-2026-76889 · CVE-2026-76885 · CVE-2026-76884

Detailed research, CV, and contact information live at caveeroo.dev.

Pinned Loading

  1. gv_decryptor gv_decryptor Public

    Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

    Python 4 1

  2. ctfd-rewind ctfd-rewind Public

    Interesting insights on CTFd competitions.

    Python 7

  3. Infractory-TFG Infractory-TFG Public

    Responsibly automated red team infrastructure management. Unmaintained.

    Java