Offensive Security Researcher

Prakhar.

Breaking to build safer.

Vulnerability researcher focused on web application security. Reported 100+ valid vulnerabilities across Fortune 500 companies and government organisations through responsible disclosure.

100+Valid Vulnerabilities
Disclosed
10+CVEs Authored
(2025)
#100India — HackerOne
Leaderboard 2025
Top 5%Globally on
TryHackMe
01 // Track Record

Hall of Fame

Google
Google
Privilege Escalation
United Nations
United Nations
PII Leak — 1M+ Records
US DoD
US Dept. of Defence
PII Leak & Account Takeovers
NASA
NASA
Multiple Account Takeovers
Netherlands Government
Netherlands Gov.
Internal Server Access (SSRF)
Starbucks
Starbucks
Information Disclosure
LeetCode
LeetCode
Business Logic Exploitation
Groww
Groww
Information Disclosure
City of Los Angeles
City of Los Angeles
Access Controls & PII
Mars
Mars
PII Exposures
Stanford University
Stanford University
Account Takeovers
MTN
MTN
LFI & Info Exposure
Kaseya
Kaseya
Account Takeover
Sony
Sony
Remote Code Execution
Informatica
Informatica
Critical PII Exposure
Hilton
Hilton
Code Injection
British Airways
British Airways
Information Disclosure
Supabase
Supabase
Security Misconfiguration
Discourse
Discourse
Security Misconfiguration
& more programs
CLASSIFIED
02 // Experience

Work Experience

Security ResearcherJun 2024 – Present
HackerOne (Independent)
Remote
  • Discovered and responsibly disclosed 100+ valid vulnerabilities across Fortune 500 and government organisations — Google, Sony, Starbucks, Discourse, British Airways, Informatica, United Nations, Supabase, US Dept. of Defence, and more.
  • Identified high-impact vulnerabilities including RCE, IDOR, Auth Bypass, Privilege Escalation, SSRF, and PII Exposure (1M+ users).
  • Authored 10+ CVEs affecting widely deployed open-source software including Gitea, Frappe, Chamilo, and SuiteCRM.
  • Ranked Top 100 security researchers in India (2025) on HackerOne.
  • Produced structured vulnerability reports covering CVSS scoring, MITRE ATT&CK mapping, business impact analysis, and step-by-step remediation.
Open Source ContributorJan 2026 – Present
OWASP Foundation — Project Cornucopia
Remote · github.com/OWASP/cornucopia
  • Designed and shipped a Swagger API (/api/docs) endpoint for WebApp and MobileApp editions.
  • Resolved SSR failures and navigation inconsistencies across web and mobile editions.
  • Implemented CRE API for companion Edition released in v3.1.0
  • Strengthened data integrity through schema-level input validation. Resolved Docker build and CI/CD pipeline failures; contributor across 6 releases including v3.1.0.
03 // Projects

Projects

04 // Capabilities

Skills & Tools

Offensive Security
Web PentestingAPI SecurityVAPTVulnerability ResearchBusiness LogicThreat ModellingResponsible DisclosureCVSS ScoringAttack Surface Mapping
Tools
Burp Suite ProCaidoNucleiFFUFNmapAmassMetasploitSQLMapFridaADBShodanGit
Programming & Scripting
PythonBashNode.jsCSQL
Frameworks & Standards
OWASP Top 10MITRE ATT&CKNIST CSFCVE/NVDPTESCVSS v3.1
Cloud & Infrastructure
Linux (primary OS)DockerCI/CD PipelinesAWS FundamentalsAPI Security
05 // Research

CVEs Authored

06 // Testimonials

What Programs Say

"Clear, well-documented report with a clean PoC, professional communication throughout, and a diligent retest to confirm the fix. A pleasure to work with."

"Professional, high quality, and well written reports from Prakhar0x01. Thank you for your time and dedication. Anytime I come across one from Prakhar0x01 I already know it's going to be a good report."

"Thank you Prakhar for reporting issues on our platform and making our business systems safer. Keep up the good work."

"This hacker's reports are very well written. The steps to reproduce are always clear and easy to follow. Additionally, this hacker maintains a professional and friendly behaviour in all communications."

07 // Writing

Write-ups & Blogs

View All Posts →
08 // Links

Explore