Security Researcher

Justin Willhite

Justin Willhite

@thejdubb02

Independent security researcher. I read source to find real, reproducible vulnerabilities in open-source software, then disclose them responsibly and ship minimal, tested fixes. Focus on access-control and IDOR flaws, server-side request forgery, and injection.

Selected work

MERGED

changedetection.io, PR #4336

Fixed the Browser Steps picker so it can select a control nested inside a container element. Reviewed and merged upstream. View PR

COORDINATED

Disclosures in progress

Source-review findings, including access-control (IDOR) and server-side request forgery issues, reported to the affected projects through their security advisory and disclosure channels. Details published once fixed.

Focus areas

Access control and IDOR SSRF Injection White-box source review Responsible disclosure

Find me