05 — Publications & Achievements

Achievements

Published Research

Wild Animal Detection using YOLOv8

Brahm Dave, Meet Mori, Anurag Bathani, Parth Goel

Procedia Computer Science, Volume 230, 2023, Pages 100-111
ISSN 1877-0509

DOI: 10.1016/j.procs.2023.12.065
Security Advisory High — CVSS 8.2

ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names

Discovered a High severity vulnerability in Gotenberg that allows arbitrary file rename and move via ExifTool dangerous tag blocklist bypass using group-prefixed tag names.

CVE: CVE-2026-40893 Package: gotenberg/gotenberg 12.7k Weakness: CWE-20 — Improper Input Validation Affected: <= 8.30.1  →  Patched: 8.31.0
Security Advisory High — CVSS 7.5

Privilege Escalation via Unrestricted serviceAccountName in the Kubernetes Backend

Discovered a High severity privilege escalation in Woodpecker CI: an unrestricted `serviceAccountName` in pipeline YAML let any user with push access run Kubernetes pods under an arbitrary — potentially cluster-admin — service account.

CVE: CVE-2026-61549 Package: woodpecker-ci/woodpecker 7.5k Weakness: CWE-269 — Improper Privilege Management Affected: < 3.16.0  →  Patched: 3.16.0
Security Advisory Low — CVSS 3.1

Blind SSRF in OAuth2 Avatar Synchronization via Unvalidated OIDC picture Claim

Reported a Low severity blind SSRF in Gitea's OAuth2 avatar sync: an unvalidated OIDC `picture` claim let a low-privileged user coax the server into fetching arbitrary internal URLs.

CVE: CVE-2026-23603 Package: go-gitea/gitea 57k Weakness: CWE-918 — Server-Side Request Forgery Affected: <= 1.26.4  →  Patched: 1.27.0

Best Research Paper Award

Awarded Best Research Paper by CHARUSAT for the work on Wild Animal Detection using YOLOv8.

Times of India Feature

Research on Wild Animal Detection featured on the front page of the Times of India (Feb 15, 2024).

Top 10% on TryHackMe

Achieved top 10% global ranking on the TryHackMe cybersecurity training platform.