Skip to content
View JAE0Y2N's full-sized avatar

Block or report JAE0Y2N

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
JAE0Y2N/README.md

Jaeyoung Yun

OSS security research in the AI-agent / MCP ecosystem.

Acknowledged GitHub Security Advisories (May 2026)

Reference-tier infrastructure (largest blast radius):

GHSA Vendor Class PoC
GHSA-4m3j-875h-rwg6 modelcontextprotocol/python-sdk (Anthropic-governed reference SDK) CWE-770 pre-auth memory exhaustion (single 500 MiB POST grows RSS 14×) Empirical, runnable
GHSA-66mv-62mm-hwrx modelcontextprotocol/typescript-sdk CWE-770 same primitive in Hono + Node adapters (Express adapter safe by default) Source-confirmed

Vendor-specific findings:

GHSA Vendor Class
GHSA-p4v8-qmvx-f922 ByteDance UI-TARS-desktop / agent-tars CWE-918 SSRF via browser_navigate
GHSA-j38f-59cc-6pm8 PrefectHQ/fastmcp CWE-352 DNS-rebinding CSRF (curl PoC)
GHSA-h7xc-pfh4-7mjv continuedev/continue CWE-78 RCE via .continue/mcpServers/*.json auto-spawn
GHSA-6h4j-54wp-57c4 continuedev/continue CWE-352 DNS-rebinding in cn serve HTTP API
GHSA-j327-qp7v-xj94 run-llama/llama_index CWE-94 pickle.load on shared persist_dir
GHSA-43x5-wwvx-7g3m mlflow/mlflow CWE-22 zipslip
GHSA-hfj5-88mp-26jq cloudflare/workers-sdk CWE-732 credential-file permissions
GHSA-2h7j-3573-w5f2 browser-use/browser-use CWE-732 Gmail-token leak
GHSA-79w5-8gp7-73mp FlowiseAI/Flowise CWE-732 master encryption key world-readable

Plus 7+ more (full ledger 18 entries) across cline, prisma, replicate, hexclave/stack-auth, agentmail-to, upbit-official/upbit-cli, tursodatabase/turso-cli.

Hardening PRs (filed alongside advisories)

Contact

  • imjyy2.0@gmail.com
  • West Vancouver, BC (Pacific time, UTC-8)

@JAE0Y2N's activity is private