Security Researcher · Web/AppSec
Breaking things in the Philippines 🇵🇭 · @ deco
$ whoami
handle : cucumbersalad
role : security researcher
motto : "if it parses input, it has a bug"Security researcher focused on vulnerability discovery and proof-of-concept development. I find bugs in real-world web apps, IoT firmware, and popular frameworks, then write reproducible PoCs so defenders can patch fast.
| CVE | Target | Class | PoC / Ref |
|---|---|---|---|
| CVE-2025-13796 | deco-cx apps — analyticsScript.ts |
Server-Side Request Forgery (SSRF) | PoC |
| CVE-2025-12917 | TOZED ZLT T10 / T10PLUS router — Reboot Handler | IoT / firmware | Advisory |
| CVE-2025-69284 | Plane (plane.io) — Workspace Members API | Improper Access Control (CWE-284) · member enumeration | Advisory |
| CVE-2025-14660 | DecoCMS Mesh — createTool Workspace Domain Handler |
Improper Access Control | Advisory |
- recon-toolkit — Shell-based reconnaissance tooling for asset discovery & enumeration.
- SnaKédex — Open-data API for expert-verified Philippine snake sightings.
- Riding Coda's Invite Emails Through a Company's Own Support Inbox · Jul 2026
- Account Takeover via a Password Reset That Trusts an Onboarding ID · Jul 2026
- Unauthenticated WebSocket Broadcasting Live Customer Chats · Jul 2026
- Path Traversal via JSON Body Parameter to Access Internal Actuator Endpoints · Apr 2026
- Unauthenticated Access to DataHub with Full CRUD Permissions · Apr 2026



