Skip to content
View Christbowel's full-sized avatar
💭
Attempting to explain to my mom that "hacking" is my actual job
💭
Attempting to explain to my mom that "hacking" is my actual job

Block or report Christbowel

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
christbowel/README.md

Typing SVG


GitHub Website HackerOne Bugcrowd

TryHackMe Root-Me Profile Views


whoami

┌──(christbowel㉿kali)-[~]
└─$ cat about.txt

  Name     : Christ Bowel Bouchuen
  Age      : xx
  Location : Darmstadt, Germany
  Uni      : TU Darmstadt — B.Sc. Computer Science
  Focus    : Offensive Security | Vulnerability Research | Bug Bounty

  CVEs Discovered  : 7
  Hall of Fames    : 5 (🇺🇸 State of California · 🇩🇪 Deutsche Telekom · 🌍 Mars VDP · 🇦🇺 RMIT · 🇺🇸 BIA)
  CTF Best Rank    : Top 15/454 — Bugcrowd Black Hat USA CTF 2024 && Top 1 - USD Hacking Night
  Status           : Software Security @ PAYONE GmbH

CVE Highlights

Six highlights below. Thirteen CVEs assigned in total.

  • CVE-2026-56111 · Marlin firmware. Out-of-bounds write; memory corruption validated on real STM32 hardware.
  • CVE-2026-49143 · browserstack-runner. Node VM sandbox escape to unauthenticated RCE. CVSS 8.7.
  • CVE-2026-49144 · browserstack-runner. Path traversal to unauthenticated file read; full host compromise when chained.
  • CVE-2026-67195 · FINOS Perspective. eval injection in PolarsVirtualServer; unauthenticated RCE.
  • CVE-2026-39911 · Hashgraph Guardian. Unsandboxed Function() to authenticated RCE, credential leak, and auth token forgery.
  • CVE-2024-29643 · Croogo CMS. Host Header Injection to RCE.

Seven more across Guardian, Perspective, and other targets.

Reported and Fixed

Vulnerabilities disclosed and patched by maintainers, no CVE assigned.

  • OWASP Dependency-Track · IDOR, confused deputy, and multi-team permission union across v4.14 and v5 (Hyades). Coordinated with maintainers and VulnCheck.
  • Symfony · Deserialization trampoline through nested unserialize(), bypassing allowed_classes. Coordinated with a core maintainer.

Selected Work

  • OSDC (Open Source Daily Catch) · Automated silent-patch detection. Scrapes the GitHub Advisory Database and diffs quiet fixes to surface n-days before they go public. The pipeline behind much of the CVE output above.
  • Diffuse · Decentralized AI inference protocol in Rust. TEE, Shamir secret sharing for prompt fragmentation, and ZK execution proofs, so inference runs without any single party ever seeing plaintext. Architecture and specification stage.

Elsewhere

1st place, usd Hacking Night CTF. Halls of Fame across public and federal disclosure programs. Coordinated Vulnerability Disclosure through VulnCheck.

📊 Stats



GitHub Streak


📈 Activity Graph

Activity Graph



♟️ Chess move of the day

Chess.com

Schach Club · TU Darmstadt ♟️


💬 Quote

Readme Quotes


🌍 Langues

🇫🇷 Français 🇩🇪 Deutsch 🇬🇧 English
Langue maternelle C1 Fließend Fluent

"Security is not a product, but a process."

Popular repositories Loading

  1. CVE-2023-25136 CVE-2023-25136 Public

    OpenSSH 9.1 vulnerability mass scan and exploit

    Python 107 21

  2. Red-Teamer Red-Teamer Public

    Red Teaming tools and techniques

    58 12

  3. CVE-2024-25600_Nuclei-Template CVE-2024-25600_Nuclei-Template Public

    Nuclei template and information about the POC for CVE-2024-25600

    31 6

  4. Blue-Teamer Blue-Teamer Public

    Blue teamer tools and techniques

    10 4

  5. CipherBuster CipherBuster Public

    Outil d'analyse et d'exploitation des vulnérabilités des implémentations RSA, avec techniques d'attaque automatisées et avancées

    Python 5 4

  6. OSDC OSDC Public

    Automated patch intelligence - tracks what gets fixed in open source daily, extracts vulnerability patterns, and detects recurring antipatterns across languages and ecosystems. Powered by GitHub Ad…

    Jinja 5 1