Public research

Evidence files from real security work.

These case studies preserve the reasoning: what was observed, which boundary was tested, and what impact was safely demonstrated.

Selected public record. Private program evidence stays private.

Source / path / proof

The useful part is how the evidence connects.

100+Validated reportsPublicSelected case studiesDisclosure-led research

Published case files

Selected public records
01
Statusresolved

Responsible disclosure

NASA GLOBE Observer Stored XSS Case Study

stored-xsscross-client-data-flowmobile-inputpublic-web-renderer

How a mobile observation comment became stored XSS on a public NASA GLOBE web page, with verified impact, root cause, and remediation.

02
Statuspublic

Research challenge

Intigriti 0526: Unintended Stored XSS Bypass

stored-xssunsafe-dom-sinkprofiletestimonial-feed

An unintended stored XSS path in Intigriti Challenge 0526 involving unsafe innerHTML, observed SCA Shield bypass behavior, and sink-side remediation.

03
Statuspublic

Case study

Blind Stored XSS Through a Text File Upload

stored-xssfile-uploaddocument-previewinternal-review

How an accepted text file rendered as HTML became blind stored XSS inside an internal review workflow.

How the evidence is handled

Public-safe by design.

Sensitive program details, customer information, credentials, and exploit material are never published. The useful lesson remains: the data flow, failed assumption, validation method, and remediation principle.