Skip to content

Latest commit

 

History

11 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Security Research

Coordinated disclosures and security writeups by @kasparovabi

Disclosures

Date Vendor / Product Severity Title Status
2026-04-29 BasedHardware / Omi CVSS 10.0 (Critical) Seventeen Vulnerabilities in Omi, Fourteen Days of Silence Mostly fixed as of 2026-08-10; OMI-15 open (update)

Provenance

For the Omi disclosure, a separate page documents the full timeline with checkable artifacts: who reported what, when, and what the vendor's own commit history says about where the fix came from. Every claim there can be reproduced with a git log command.

Methodology

Each writeup in this repository is published after:

  1. A private report through the vendor's preferred coordinated-disclosure channel (typically GitHub Security Advisories).
  2. A reasonable window for the vendor to acknowledge, triage, and patch.
  3. A public-disclosure date communicated to the vendor in advance.

Where the vendor refuses to act, the disclosure window is shortened in proportion to the vendor's behavior, the public exposure of the affected code paths, and the regulatory clocks that may apply to affected users (HIPAA, GDPR, SOC 2 audit obligations).

No proof-of-concept exploit code is published in this repository. Technical detail is sufficient to reproduce findings against the source code; no payload, weaponized scanner, or live-target tooling is included.

Contact

  • GitHub: @kasparovabi
  • Email: kasparovabi@gmail.com
  • For security reports about my own code, please open a private GitHub Security Advisory on the relevant repository.

About

Security research and coordinated disclosures by @kasparovabi

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages