Independent security researcher

Mongolia UTC+8

Sukhbat Zundui · deprrous / Hackratic / C47 / R47

I break trust assumptions.

Web and application security research with public work across open-source ecosystems, bug bounty programs, and competitive CTFs.

04 Public CVEs
06 GitHub advisory credits
7.5 Highest public CVSS
#01 AITU international qualifier / C47

Evidence standard / no self-rating Public claims link to advisories, merged patches, verified profiles, or official scoreboards. Private experience is labeled clearly and never presented as public proof.

00 / Professional experience

01 year

Secure the
systems I run.

Onlime Network LLC ↗

DevOps Engineer · Systems Engineer · White-box Security Testing

Engineering and securing production telecommunications systems in Mongolia. Responsibilities combine infrastructure operations with source-assisted security assessments and remediation work across internal product teams.

Education Fourth-year undergraduate MUST · School of Information and Communication Technology ↗

Internal findings remain confidential; only role scope and public products are listed.

01 / Public record

Research that
shipped a fix.

Published findings credited to deprrous. Each entry links to a public advisory or disclosure rather than a private claim.

R/01
High CVE-2026-32995 CWE-639

Rocket.Chat private-message access control bypass

An authorization flaw in autoTranslate.translateMessage exposed message content outside the caller’s room membership. Reported through HackerOne and resolved by Rocket.Chat.

HackerOne CVSS 7.5 Read disclosure
R/02
High GHSA-xmf8-cvqr-rfgj CWE-20

Auth.js malformed Bearer header denial of service

A malformed authorization header could make getToken() throw an uncaught exception, turning invalid input into per-request availability loss.

Auth.js CVSS 7.5 Read advisory
R/03
High CVE-2026-33036 CWE-776

fast-xml-parser entity expansion limit bypass

Numeric and standard XML entities bypassed expansion limits, allowing crafted input to consume disproportionate CPU and memory despite an earlier fix.

Open source CVSS 7.5 Read advisory
R/04
Medium CVE-2026-55443 CWE-22 / 59

LangChain path traversal and sandbox escape

File-search middleware and loaders did not consistently confine resolved paths to their intended roots, enabling traversal through patterns and symlinks.

Co-credited CVSS 5.1 Read advisory
R/05
Low CVE-2026-41488 CWE-918

LangChain image-token SSRF via DNS rebinding

Separate DNS resolution during URL validation and image fetching created a TOCTOU window that could redirect a permitted hostname to an internal address.

LangChain CVSS 3.1 Read advisory
R/06
Medium 2 advisories CWE-79

pdfme schema injection XSS variants

Two independent unsafe innerHTML paths in SVG and select schemas allowed attacker-controlled template values to execute script in consuming UIs.

Bug bounty / verified record

Five validated findings.
Two platforms.

Four findings appear across the public HackerOne profiles. One additional valid Immunefi report remains private and is labeled separately.

05validated across platforms
04public HackerOne findings
02public HackerOne profiles
01private Immunefi finding
Immunefi / private disclosure 01 valid Low finding Researcher-confirmed · project and technical details withheld

HackerOne publicly verifies the Supabase and Vercel resolutions. Supabase Medium 4.3, Vercel Medium 6.3 / Tier 1, and the Immunefi Low result include researcher-confirmed private metadata; technical disclosure content is intentionally omitted.

02 / Competitive security

One team.
Many flags.

CTF competitor with Hackratic, appearing on the C47 roster in Web / Crypto. Also competes under the related C47 and R47 names.

HACKRATIC/C47/R47
Hackratic / 2026 signal Updated Jul 2026
Overall rating #27 455.552 pts
Mongolia #03 country place
AITU CTF Qualifier #03 #1 international / 270 listed
AITU CTF Final #10 C47 / 20 finalists
VolgaCTF Qualifier #09 qualified for September final
HackDay Qualifier #24 top 25 / 185 teams
Events 36 during 2026
Next / 14–18 Sep 2026 VolgaCTF Final

Hackratic qualified in 9th place and plans to attend the in-person final in September.

Official qualifier ↗
Qualified / Mar 2026 HackDay Final

Hackratic finished 24th of 185, inside the 25-team cutoff, but could not attend the Paris final because travel funding was unavailable.

Qualification record ↗
Mongolian CTF circuit / team-supplied record Final & Stage 2 appearances

Advanced beyond qualification rounds in multiple domestic competitions. This records progression only; no podium placement is claimed.

Team metrics are Hackratic results, not individual rankings. Sources: Hackratic, CTFtime, and AITU.

03 / Built in public

Code that
landed.

Maintainer-accepted fixes and public tools, linked directly to the upstream record.

AutheliaMerged

PR #11500

Prevent OTC DELETE nil-pointer panic

Reported the crash path that led to the merged fix and a maintainer-added public bug-contributor credit.

libpcapMerged · Jul 2026

PR #1709

Restore Clang diagnostic state

Fixed the missing pragma-pop helper for uninitialized const-pointer diagnostics, validated against the Clang preprocessor output.

04 / Operating profile

Think adversarial.
Report responsibly.

I’m Sukhbat Zundui, known as deprrous, a Mongolia-based security researcher focused on finding the gap between what software assumes and what an attacker can control.

My public work spans authorization, path boundaries, parser limits, SSRF, and client-side injection. I hunt across open-source projects and coordinated disclosure programs, including HackerOne and Immunefi.

Outside research, I compete with Hackratic and its C47 / R47 rosters, primarily across web and cryptography challenges.

This portfolio is a factual record, not a self-assigned ranking. Public work links to its source; private responsibilities are identified without exposing internal details.

I also prepare upstream fixes for Google’s OSS Patch Rewards program. No Google reward is claimed here unless it appears in the public rewarded-patches record.

05 / Contact

Have a hard
security problem?

Open to research collaboration, security engineering, and CTF conversations.