Security vulnerability research by Charles Vosburgh / the-vibe-dev.
This repository is the authoritative public portfolio for Charles's CVE and repository-level GitHub Security Advisory work. Accepted Linux kernel security fixes are documented separately in the-vibe-dev/Linux-Kernel.
| Metric | Verified public count |
|---|---|
| Distinct public vulnerability cases | 31 |
| Public CVEs | 23 |
| Published repository GHSAs | 14 |
| Cases carrying both CVE and GHSA identifiers | 6 |
One vulnerability is represented by one canonical directory. When the same case has both a CVE and a repository GHSA, both identifiers appear in that directory rather than being counted as separate vulnerabilities.
The six overlap cases are TypeBox, isomorphic-git, both public vm2 cases, fast-xml-parser, and libheif. Accordingly, 23 CVEs + 14 GHSAs does not equal 37 vulnerabilities. The correct total is 31 distinct public cases: 14 repository-GHSA cases plus 17 other public CVE cases.
Global GitHub Advisory Database mirrors created from CVE records are useful references, but they are not counted as researcher-contributed repository advisories.
| # | Identifier(s) | Project | Public finding | Public severity | Write-up state | Write-up |
|---|---|---|---|---|---|---|
| 01 | CVE-2026-73343 |
WP Compress | Unauthenticated remote code execution | Critical, 10.0 | Summary-only | Read |
| 02 | CVE-2026-15054 |
Bit Form | Inactive or unpublished forms remained reachable through public submission handlers | Low, 3.7 | Full | Read |
| 03 | CVE-2026-16534 |
Import and export users and customers | CSV import authorization failure | High, 7.2 | Full | Read |
| 04 | CVE-2026-64606 |
Apache Fory | Java lambda class-registration bypass | Important (Apache) / Critical, 9.8 (CISA ADP) | Full | Read |
| 05 | CVE-2026-75796 |
AI Engine | Multisite account-target authorization failure | High, 7.2 | Full | Read |
| 06 | CVE-2026-77789 |
Stripe Payment Forms by WP Full Pay | Cross-customer subscription modification | Medium, 4.3 | Full | Read |
| 07 | CVE-2026-77356 · GHSA-976x-prgx-qv35 |
TypeBox | Generated validation-code injection | High, 7.8 | Full | Read |
| 08 | CVE-2026-77355 · GHSA-6fxm-h49m-4fg3 |
isomorphic-git | NTFS alias bypass writing into the active gitdir | High, 8.8 | Full | Read |
| 09 | CVE-2026-47698 · GHSA-cfcw-xp6x-25gj |
vm2 | Sandbox breakout through dangerous host prototype mutators | Critical, 9.8 | Full | Read |
| 10 | CVE-2026-73569 · GHSA-8r6m-32jq-jx6q |
fast-xml-parser | Repeated DOCTYPE declarations reset entity-expansion limits |
High, 8.7 | Full | Read |
| 11 | GHSA-5jx8-p6q2-455g |
DynamicExpresso | LateBindObject reflection-restriction bypass |
High, 8.8 | Full | Read |
| 12 | GHSA-hphq-wq62-4mj3 |
OpenEXR | HTJ2K planar decode row-endpoint wrap causing denial of service | Moderate, 5.5 | Full | Read |
| 13 | GHSA-v3qq-3xvg-m77g |
python-statemachine | Restricted-evaluator write-side dunder traversal | Critical, 9.1 | Full | Read |
| 14 | GHSA-fj3w-533r-fvf6 |
python-statemachine | Untrusted SCXML external-source local-file disclosure | High, 7.1 | Full | Read |
| 15 | GHSA-g3jj-5cmm-3hxx |
fast-jwt | Raw public JWK JSON accepted as an HMAC secret | High, 7.4 | Full | Read |
| 16 | CVE-2026-92948 · GHSA-qhwx-74w5-xhxq |
vm2 | NodeVM builtin allowlist bypass through node:test.run() |
Critical, 9.9 | Full | Read |
| 17 | CVE-2026-81766 |
Really Simple Security | Multisite subsite Administrator plugin installation | Medium, 6.6 | Full | Read |
| 18 | CVE-2026-17563 |
WP User Frontend | Unauthenticated post creation through a subscription-gated form | Not displayed by WPScan | Full | Read |
| 19 | CVE-2026-77793 |
RegistrationMagic | Paid-registration bypass through an omitted price field | Not displayed by WPScan | Full | Read |
| 20 | GHSA-9v3x-mhg4-wwv2 |
Exiv2 | Out-of-bounds stack access in built-in HTTP request construction | Low | Full | Read |
| 21 | CVE-2026-84451 · GHSA-hh47-fhqr-cj2r |
libheif | Incomplete range-check fix allowed integer wrap and out-of-bounds read | Moderate, 6.5 | Full | Read |
| 22 | CVE-2026-86815 |
BackWPup | Missing authorization on a backup-management operation | Medium, 5.5 | Summary-only | Read |
| 23 | CVE-2026-88764 |
Simple Membership | Improper privilege management | Medium, 5.4 | Summary-only | Read |
| 24 | CVE-2026-89080 |
Really Simple Security | Email two-factor authentication bypass | High, 7.5 | Summary-only | Read |
| 25 | GHSA-w2cx-738m-mc7w |
PyJWT | Public JWK containers accepted as HMAC verification secrets | High, 7.4 | Full | Read |
| 26 | GHSA-r2q2-xmpm-7fvh |
SimpleEval | Restricted-expression callable denylist bypass | Low | Full | Read |
| 27 | CVE-2026-92403 |
Secure Custom Fields | Unauthenticated post modification via front-end form ID substitution | Low, 3.7 | Summary-only | Read |
| 28 | CVE-2026-92400 |
Payment Gateway for PayPal on WooCommerce | Unauthenticated payment bypass via sandbox IPN environment confusion | Not displayed by WPScan | Summary-only | Read |
| 29 | CVE-2026-81810 |
All-in-One WP Migration and Backup | Configured export-only user privilege escalation to administrator | High, 7.2 | Summary-only | Read |
| 30 | CVE-2026-90922 |
Paid Member Subscriptions | PayPal amount and currency mismatch accepted for paid membership | Medium, 5.3 | Summary-only | Read |
| 31 | CVE-2026-85569 |
Tutor LMS | Read-only API key privilege escalation via REST request misclassification | High, 7.2 | Summary-only | Read |
Twenty-two cases have full technical write-ups based on already-public advisories, commits, releases, and public proof material. Nine cases remain high-level summaries because their coordinators have not yet released the corresponding PoC or sufficient technical detail:
| Case | Current public gate |
|---|---|
WP Compress / CVE-2026-73343 |
Confirm Patchstack's detailed-release state before publishing private root-cause or PoC material. |
BackWPup / CVE-2026-86815 |
WPScan says the PoC will be displayed September 23, 2026. Re-check the live page before expansion. |
Simple Membership / CVE-2026-88764 |
WPScan says the PoC will be displayed September 25, 2026. Re-check the live page before expansion. |
Really Simple Security email 2FA / CVE-2026-89080 |
WPScan says the PoC will be displayed October 11, 2026. Re-check the live page before expansion. |
Secure Custom Fields / CVE-2026-92403 |
WPScan says the PoC will be displayed October 1, 2026. Re-check the live page before expansion. |
Payment Gateway for PayPal on WooCommerce / CVE-2026-92400 |
WPScan says the PoC will be displayed October 1, 2026. Re-check the live page before expansion. |
All-in-One WP Migration and Backup / CVE-2026-81810 |
WPScan says the PoC will be displayed October 16, 2026. Re-check the live page before expansion. |
Paid Member Subscriptions / CVE-2026-90922 |
WPScan says the PoC will be displayed September 29, 2026. Re-check the live page before expansion. |
Tutor LMS / CVE-2026-85569 |
WPScan says the PoC will be displayed October 14, 2026. Re-check the live page before expansion. |
A date passing does not automatically clear a write-up. The coordinator's live public page controls publication. WPScan now displays the PoCs for CVE-2026-17563, CVE-2026-77793, and CVE-2026-75796; those reports were expanded using the public material in this refresh.
Each directory under findings/ represents one distinct vulnerability and contains a public README.md. Cases with both identifiers keep the CVE and GHSA together. The repository intentionally excludes raw private evidence, correspondence, unpublished exploit material, credentials, and embargoed artifacts.
The write-ups distinguish:
- maintainer-published claims from independently verified evidence;
- affected ranges from directly sampled releases;
- the demonstrated primitive from conditional downstream impact;
- vulnerable behavior from negative and fixed controls;
- finder, reporter, co-reporter, verification, and patch-author roles; and
- already-public proof material from research that remains withheld.
The goal is a precise account of the failed security boundary, the public impact, and how the remediation restores the intended invariant.
Charles Vosburgh — the-vibe-dev
Independent security researcher focused on authorization boundaries, sandbox escapes, parser and deserialization behavior, generated-code injection, WordPress attack surfaces, protocol security, and reproducible vulnerability validation.
Charles also develops SecHive.ai, an operator-driven security research workbench focused on scoped analysis, reproducible validation, evidence retention, remediation review, and human-controlled disclosure decisions.
Technical material in this repository is intended for defensive analysis, remediation, regression testing, patch verification, and systems the reader owns or is explicitly authorized to assess.
