Skip to content
View 0xcucumbersalad's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report 0xcucumbersalad

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xcucumbersalad/README.md

Jaynel Patiarba

Security Researcher · Web/AppSec
Breaking things in the Philippines 🇵🇭 · @ deco


whoami

$ whoami
handle   : cucumbersalad
role     : security researcher
motto    : "if it parses input, it has a bug"

Security researcher focused on vulnerability discovery and proof-of-concept development. I find bugs in real-world web apps, IoT firmware, and popular frameworks, then write reproducible PoCs so defenders can patch fast.


Published CVE Research

CVE Target Class PoC / Ref
CVE-2025-13796 deco-cx appsanalyticsScript.ts Server-Side Request Forgery (SSRF) PoC
CVE-2025-12917 TOZED ZLT T10 / T10PLUS router — Reboot Handler IoT / firmware Advisory
CVE-2025-69284 Plane (plane.io) — Workspace Members API Improper Access Control (CWE-284) · member enumeration Advisory
CVE-2025-14660 DecoCMS Mesh — createTool Workspace Domain Handler Improper Access Control Advisory

Featured Projects

  • recon-toolkit — Shell-based reconnaissance tooling for asset discovery & enumeration.
  • SnaKédex — Open-data API for expert-verified Philippine snake sightings.

Arsenal

Python TypeScript Bash Burp Suite Nmap Linux


Certifications

WAPTX HTB CBBH PWPP CAPenX ACP CNSP CAP


Latest Writeups


0xcucumbersalad.dev

Pinned Loading

  1. apps apps Public

    Forked from deco-cx/apps

    Open-Source MCP apps powering https://decocms.com

    TypeScript

  2. CVE-2025-13796-PoC CVE-2025-13796-PoC Public

    deco-cx apps Parameter analyticsScript.ts AnalyticsScript server-side request forgery

  3. mesh mesh Public

    Forked from decocms/studio

    One secure endpoint for every MCP server. Deploy anywhere.

    TypeScript