// offensive security researcher

Prakhar.

aka prakhar0x01

Offensive security researcher with 2+ years of hands-on vulnerability research, web & API penetration testing, and responsible disclosure across Fortune 500 companies and government organisations. Reported 100+ valid vulnerabilities and authored 10+ CVEs in widely deployed software. Ranked Top 100 security researchers in India on HackerOne (2025).

Top 100 India — HackerOne 2025 Top 5% — TryHackMe 10+ CVEs — 2025 OWASP Contributor
▾ scroll
100+ Valid Vulnerabilities
Disclosed
10+ CVEs Authored
(2025)
#100 India — HackerOne
Leaderboard 2025
Top 5% Globally on
TryHackMe
01 // track_record

Hall of Fame

Google
Google
Privilege Escalation
United Nations
United Nations
PII Leak — 1M+ Records
US DoD
US Dept. of Defence
PII Leak & Account Takeovers
NASA
NASA
Multiple Account Takeovers
Netherlands Government
Netherlands Gov.
Internal Server Access (SSRF)
Starbucks
Starbucks
Information Disclosure
LeetCode
LeetCode
Business Logic Exploitation
Groww
Groww
Information Disclosure
City of Los Angeles
City of Los Angeles
Multiple Access Controls & PII Exposures
Mars
Mars
PII Exposures
Stanford University
Stanford University
Account Takeovers
MTN
MTN
LFI & Information Exposure
Kaseya
Kaseya
Account Takeover
Sony
Sony
Remote Code Execution (RCE)
Informatica
Informatica
Critical PII Exposure
Hilton
Hilton
Code Injection
British Airways
British Airways
Information Disclosure
& more programs
[confidential]
02 // experience

Work Experience

Security Researcher Jun 2024 – Present
HackerOne (Independent)
Remote
  • Discovered and responsibly disclosed 100+ valid vulnerabilities across Fortune 500 and government organisations — Google, Sony, Starbucks, Discourse, British Airways, Informatica, United Nations, Supabase,US Dept. of Defence, and more.
  • Identified high-impact vulnerabilities including RCE, IDOR, Auth Bypass, Privilege Escalation, SSRF, and PII Exposure (1M+ users); each submission delivered with full PoC, reproduction steps, impact assessment, and remediation guidance.
  • Authored 10+ CVEsCVE-2025-59541, CVE-2025-59542, CVE-2025-59543, CVE-2025-64489, CVE-2025-64490, CVE-2026-12895, CVE-2026-58507, CVE-2026-23603, CVE-2026-57897, CVE-2026-58437, CVE-2026-58424 — affecting widely deployed open-source software.
  • Ranked Top 100 security researchers in India (2025) on HackerOne.
  • Produced structured vulnerability reports covering CVSS scoring, MITRE ATT&CK mapping, business impact analysis, and step-by-step remediation.
Open Source Contributor Jan 2026 – Present
OWASP Foundation — Project Cornucopia
Remote · github.com/OWASP/cornucopia
  • Designed and shipped a Swagger API (/api/docs) endpoint for WebApp and MobileApp editions, improving API discoverability and enabling automated integration testing.
  • Resolved SSR failures and navigation inconsistencies across web and mobile editions through version and language routing for card pages.
  • Implemented CRE API for companion Edition released in v3.1.0
  • Strengthened data integrity through schema-level input validation, preventing database truncation errors in production. Resolved Docker build and CI/CD pipeline failures; contributor across 6 releases including v3.1.0.
03 // projects

Projects

04 // technical_skills

Skills & Tools

Offensive Security
Web PentestingAPI Security VAPTVulnerability Research Business LogicThreat Modelling Responsible DisclosureCVSS Scoring Attack Surface Mapping
Tools
Burp Suite ProCaido NucleiFFUF NmapAmass MetasploitSQLMap FridaADB ShodanGit
Programming & Scripting
PythonBash Node.jsCSQL
Frameworks & Standards
OWASP Top 10MITRE ATT&CK NIST CSFCVE/NVD PTESCVSS v3.1
Cloud & Infrastructure
Linux (primary OS)Docker CI/CD PipelinesAWS Fundamentals API Security
05 // cve_authored

Security Research

07 // testimonials

What Programs Say

"Clear, well-documented report with a clean PoC, professional communication throughout, and a diligent retest to confirm the fix. A pleasure to work with."

"Professional, high quality, and well written reports from Prakhar0x01. Thank you for the your time and dedication identifying and reporting vulnerabilities. Anytime I come across one from Prakhar0x01 I already know it's going to be a good report. Thank you."

"Thank you Prakhar for reporting issues on our platform and making our business systems safer. Keep up the good work."

"This hacker's reports are very well written. The steps to reproduce are always clear and easy to follow, making the triage process smoother. Additionally, this hacker maintains a professional and friendly behaviour in all communications, which is greatly appreciated."

08 // latest_posts

Write-ups & Blogs

View All Posts →
09 // explore

Explore My Work