mitsec
available for private programs

Breaking things
on purpose —
then writing the fix.

I'm Yunus Emre Öztaş (@ynsmroztas / mitsec) — a security researcher and bug bounty hunter. I hunt critical bugs across web, mobile and API surfaces, and I ship the zero-dependency tooling I use to find them.

mitsec@kali — ~/recon
100+HOF Entries
2430+Vulns Reported
1100+P1 Critical
12+Years Exp
APPLEMICROSOFTMETAIBMINTIGRITIYESWEHACKBUGCROWDHACKERONET-MOBILESBBTÜV RHEINLANDHARMANAPPLEMICROSOFTMETAIBMINTIGRITIYESWEHACKBUGCROWDHACKERONET-MOBILESBBTÜV RHEINLANDHARMAN

Arsenal

Tools I built & use daily

all tools →

NextSniper

exploit

Next.js exploitation scanner — CVE-2025-29927 & CVE-2025-55182 middleware bypass + RSC traversal modules. Confirmed RCE on production AWS EC2.

Python · stdlib onlygithub ↗

FridHunter

mobile

Rootless Android pentest suite via Frida Gadget injection on Termux. 8-layer SSL pinning bypass, secret scanner, schema-aware deeplink fuzzer, autopilot.

Python · stdlib onlygithub ↗

NextScope

recon

Next.js / Vercel bundle intelligence — chunk harvesting, source-map recovery, endpoint & secret extraction with an HTML report per target.

Python · stdlib onlygithub ↗

HeaderHunter

scanner

POST endpoint discovery + HTML form parsing with body-parameter injection across SQLi / XSS / SSTI / RCE / LFI / CRLF / Open Redirect.

Python · stdlib onlygithub ↗

FortiSniper

exploit

CVE-2026-21643 scanner for FortiClientEMS — PostgreSQL injection via Site header, CAST-trick error extraction, time-based blind fallback.

Python · stdlib onlygithub ↗

ShodanMap

recon

Shodan REST asset mapper — multi-query harvest, DNS domain API, IP↔port↔domain↔cert correlation and httpx target generation.

Python · stdlib onlygithub ↗

Writeups

Latest research notes

all writeups →
exploit2026-07-12

Chaining Email Enumeration to Full DB Dump

A low-severity user enumeration primitive escalated into an unauthenticated database dump through a chained IDOR and a leaky export endpoint.

11 min readread →
web2026-06-02

DOM Clobbering + Cross-Origin Exploit Chain

Turning a harmless HTML injection into account takeover by clobbering a script-loader config object and pivoting through a permissive postMessage handler.

9 min readread →
mobile2026-05-18

Android Pentesting Without Root — FridHunter

Gadget injection workflow on Termux: repacking, 8-layer pinning bypass, and automated secret extraction on non-rooted devices.

14 min readread →

Disclosure

CVE & research timeline

2025

CVE-2025-55182 Critical · CVSS 9.1

Next.js RSC — React Server Components deserialization leading to remote code execution.

2025

CVE-2025-29927 High · CVSS 7.5

Next.js — Middleware authorization bypass via crafted internal subrequest header.

2023

CVE-2023-38646 Critical · CVSS 9.8

Metabase — Pre-authentication remote code execution through the setup token endpoint.

2021

CVE-2021-3129 Critical · CVSS 9.8

Laravel / Ignition — Debug-mode file write chained to RCE via log poisoning.

Capability

Where I go deep

Web Application Security95%
Bug Bounty Hunting93%
Tooling & Automation92%
Mobile App Pentesting90%
Python90%
Recon & Attack Surface88%
Bash / Shell88%
Exploit Development82%
Reverse Engineering78%

Contact

Let's talk

↑↓ navigate↵ openesc close