Skip to content
View KatrielMoses's full-sized avatar

Block or report KatrielMoses

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
KatrielMoses/README.md

katriel moses

building top-tier security tooling · breaking open source & filing the CVEs

rootaccess.tech  ·  advisories


mailaccess

Email OSINT across 2500+ platforms
breach detection · identity clustering · DNS & web exposure · no API keys

pip install mailaccess

stars python
voidaccess

Self-hosted dark-web OSINT
automated threat intel · query → graph in 13 steps · relationship mapping

pip install voidaccess

stars python

notable CVEs

found by manual source review, reported privately, published after the fix shipped.

cve target class severity
CVE-2026-50112 Apache CloudStack RCE + SSRF → root on KVM host 🔴 Critical
CVE-2026-58123 Hermes WebUI unauthenticated RCE (terminal API) 🔴 Critical · 9.3
CVE-2026-53975 OpenChamber unauthenticated RCE (command injection) 🔴 Critical · 9.3
CVE-2026-53983 Ground Station blind SSRF (orbital data URL) 🔴 Critical · 9.2
CVE-2026-10142 kafka-python DoS (excessive memory allocation) 🟠 High · 8.7
more disclosures
cve target class severity
CVE-2026-45229 quark-auto-save mass assignment → credential takeover High
CVE-2026-47092 claude-hud arbitrary command execution via COMSPEC High
CVE-2026-43982 algernon path-traversal file write via savein() High
CVE-2026-43981 algernon race condition → DoS via shared LState High
CVE-2026-47091 claude-hud path traversal via transcript_path Medium
CVE-2026-45228 quark-auto-save stored XSS via system configuration Medium
CVE-2026-47090 claude-hud terminal injection via OSC 8 hyperlinks Low

full writeups → github.com/KatrielMoses/cves


free audits

open source? i'll break it for free.

you get   →  full manual source review
          →  private report with a working PoC
          →  CVE filed + advisory published, after your fix ships
          →  a note confirming the project was reviewed & patched
catch     →  it has to be open source
turnaround→  a weekend. two at most.

responsible disclosure  ·  fix first  ·  publish after

Pinned Loading

  1. voidaccess voidaccess Public

    Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and Flare.

    Python 672 93

  2. MailAccess MailAccess Public

    Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

    Python 1.2k 107

  3. CVEs CVEs Public

    Writeup for CVEs

    4

  4. xyproto/algernon xyproto/algernon Public

    Small self-contained pure-Go web server with Lua, Teal, Markdown, HTTP/2, QUIC, Redis, TypeScript, npm-less React 19, SQLite, and PostgreSQL support ++

    JavaScript 3k 151

  5. urwid/urwid urwid/urwid Public

    Console user interface library for Python (official repo)

    Python 3k 341

  6. Cp0204/quark-auto-save Cp0204/quark-auto-save Public

    夸克网盘签到、自动转存、命名整理、发推送提醒和刷新媒体库一条龙

    Python 3k 411