> whoami

Winston Crooker · 16 · Mount Vernon, WA

I don't write the code. I direct the agents that do.

Independent security researcher. I find bugs in web apps and open source, then prove they're real before I report them.

Findings and credits

By the numbers

CVEs credited
15
Programs with accepted findings
9
Merged upstream fix
1

Counted from the findings below. Every CVE links to its record on cve.org.

Findings

What I found, and what happened next.

  1. MariaDBMDEV-39762HackerOneReported 2026-05-26Medium 4.1
    Found

    Replica crash from a malformed compressed replication event

    Memory safety (32-bit size truncation into a fixed stack buffer)

    Impact

    Crashes the replica. Needs a malicious or compromised primary, or a tampered replication stream.

    Outcome

    Fixed in MariaDB 10.11.19, 11.4.13, 11.8.9 and 12.3.3 (released 2026-08-24), and 13.0.2 (2026-09-15).

    The HackerOne report is private. The public MariaDB ticket says “Reported by Winston Crooker”.

    Proofjira.mariadb.org/browse/MDEV-39762

  2. Vercel Open Source (Nuxt)HackerOneReported 2026-05-09Medium 6.9
    Found

    Other local users could read a developer's project source through the Nuxt dev server's IPC socket

    Exposure of resource to wrong sphere (local, cross-user)

    Impact

    On a shared Linux machine, another user could read source files and .env values while nuxt dev was running.

    Outcome

    Fixed in nuxt 4.4.7 and 3.21.7. Resolved 2026-06-16.

    Bounty paid by Vercel Open Source on HackerOne. The public advisory credits other reporters; my report was filed May 9, before the advisory was published on June 2.

    Proofgithub.com/advisories/GHSA-534h-c3cw-v3h9hackerone.com/winstoncrooker

    Bounty$1,000

  3. Concrete CMSCVE-2026-8204HackerOnePublished 2026-05-21Medium 6.3
    Found

    A public calendar block could be used to read private calendar data

    Authorization bypass

    Impact

    Private calendar events readable through a public page.

    Outcome

    Fixed in Concrete CMS 9.5.1.

    Proofcve.org/CVERecord?id=CVE-2026-8204Concrete CMS 9.5.1 release notes

  4. Concrete CMSCVE-2026-8236HackerOnePublished 2026-05-21Medium 6.3
    Found

    File usage endpoint had no authentication check

    IDOR, missing authentication

    Impact

    Anyone could pull page IDs, versions and URL paths by file ID, no login needed.

    Outcome

    Fixed in Concrete CMS 9.5.1.

    Proofcve.org/CVERecord?id=CVE-2026-8236Concrete CMS 9.5.1 release notes

  5. Concrete CMSCVE-2026-8240HackerOnePublished 2026-05-21Medium 6.3
    Found

    Unauthenticated page metadata leak that revealed private, draft and restricted pages

    Information disclosure

    Impact

    Private and draft pages, with their titles, paths and authors, discoverable without logging in.

    Outcome

    Fixed in Concrete CMS 9.5.1.

    Proofcve.org/CVERecord?id=CVE-2026-8240Concrete CMS 9.5.1 release notes

  6. Kiwi.comHackerOneReported 2026-05-02Low
    Found

    Cross-tenant Vault secret exposure in k8s-vault-operator

    Impact

    Low (program-rated)

    Outcome

    Fixed in k8s-vault-operator v1.6.2. $200 bounty.

    Proofkiwicom/k8s-vault-operator v1.6.2hackerone.com/winstoncrooker

  7. DuckDuckGoHackerOneReported 2026-04-05Low
    Found

    Lookalike localhost hostnames could switch off the Privacy Extension's protections

    Impact

    Low

    Outcome

    Fixed in DuckDuckGo Privacy Extension 2026.5.22.

    Proofduckduckgo-privacy-extension commit 06390d5hackerone.com/winstoncrooker

  8. CoinbaseHackerOneResolved 2026-09-15Medium 4.1
    Found

    AgentKit x402: the signed payment ignores the maxPaymentUsdc cap and is under-reported

    Impact

    Medium

    Outcome

    $200 bounty.

    Proofhackerone.com/winstoncrooker

Full CVE log

15 CVEs, each linked to its record on cve.org. Scores are the program's own CVSS 4.0 ratings.

Every CVE credited to Winston Crooker, highest score first
CVETitleClassSeverityFixed inPublished
CVE-2026-8204A public calendar block could be used to read private calendar dataAuthorization bypassMedium 6.39.5.12026-05-21
CVE-2026-8236File usage endpoint had no authentication checkIDOR, missing authenticationMedium 6.39.5.12026-05-21
CVE-2026-8240Unauthenticated page metadata leak that revealed private, draft and restricted pagesInformation disclosureMedium 6.39.5.12026-05-21
CVE-2026-81908REST API groups list skipped per-group permission checksMissing authorizationMedium 6.09.5.32026-09-11
CVE-2026-68527Calendar event editor checked the wrong calendar, so users could read and overwrite events they had no access toAuthorization bypass (IDOR)Medium 5.99.5.32026-09-10
CVE-2026-68526Calendar event duplicate accepted forged cross-site requestsCSRFMedium 5.39.5.32026-09-11
CVE-2026-84432Boards custom slot dialog accepted forged cross-site requestsCSRFMedium 5.39.5.32026-09-10
CVE-2026-8340Forged requests could switch a file to an older or unpublished versionCSRFLow 2.39.5.12026-05-22
CVE-2026-8347Users with view-only access could reorder another entity's Express associationsIDORLow 2.39.5.12026-05-22
CVE-2026-87031REST API user creation had no permission checkMissing authorizationLow 2.19.5.42026-09-16
CVE-2026-18421Board editors could change or delete other boards' data sourcesMissing authorizationLow 2.19.5.32026-09-15
CVE-2026-68529Express advanced search returned entries from entities the user could not viewMissing authorizationLow 2.19.5.32026-09-15
CVE-2026-68530Board instance actions skipped the parent board's permission checkMissing authorizationLow 2.19.5.32026-09-15
CVE-2026-18422Multilingual page assign had no destination check and no CSRF tokenMissing authorization, CSRFLow 2.19.5.32026-09-15
CVE-2026-18425Sitemap reorder ignored per-page edit permission and had no CSRF tokenMissing authorization, CSRFLow 2.19.5.32026-09-15

Credits and merged fix

More on HackerOne

I also have accepted reports at Netflix, Spotify and Elastic, a confidential program, and more at Vercel Open Source. These are private, so the details stay on my HackerOne profile.

“Thanks Winston Crooker for reporting.”

Concrete CMS security team, in 15 CVE records

How I work

I bring the ideas. The AI does the digging.

I work by direction. I pick the targets, form the idea of where a weakness might be and how to reach it, and tell the AI how I want it pursued. It does the heavy lifting: reading the code, chasing the lead, building the proof. I read what comes back, decide what holds up, and stand behind every report I send.

Standing rules

  1. A finding only counts when the exploit runs end to end, with unauthorized data in the response or confirmation on the victim's side.
  2. A different error message, a different status code, or a missing check in the source is never proof by itself. The exploit has to actually succeed.
  3. Before I report anything, I have the AI read the target's security documentation, so I can rule out behavior that is documented as unsafe by design or left to the developer.
  4. Every report gets an adversarial review pass, with the AI playing a skeptical triager, before I submit it.

AI-assisted reports have a bad reputation with triagers. These rules are how I keep mine out of that pile.

Writeups

Notes from the public record.

  • CVE-2026-68527

    The calendar editor checked the wrong calendar

    Concrete CMS lets a user change a calendar event through an edit dialog. In versions 8.3.0 through 9.5.2, that dialog decided whether to allow the change by checking the calendar ID sent in the request, not the calendar that actually owns the event. So a user with the "Add Event" permission on one calendar could open events on calendars they had no access to, read them, and overwrite them. They could also delete an event's original local occurrence.

    There was a limit. Publishing the changed version to the live calendar, which demotes the previously approved version, also needed approval rights for calendar events or a workflow that approves changes automatically.

    I reported it to the Concrete CMS security team. They rated it 5.9 under CVSS 4.0, and the fix shipped in 9.5.3. The CVE record has the full description.

  • CVE-2026-8240

    Private page details, readable without logging in

    In Concrete CMS 9.5.0 and below, a backend component named in the CVE title as Backend\SummaryTemplate returned page metadata to visitors who were not logged in. It did this for every page with a summary template configured, including pages that were private, still in draft, or restricted.

    For each of those pages, an anonymous visitor could confirm that the page existed and read its title, path, description and author. The record lists exactly those four fields, so this was a metadata leak, but it covered every page that had a summary template, whatever its permissions said.

    I reported it to the Concrete CMS security team. They rated it 6.3 under CVSS 4.0: reachable over the network, with no login and no user interaction, and a low confidentiality impact. The fix shipped in 9.5.1, and the CVE record names me as the reporter.

  • CVE-2026-81908

    A permission check that always said yes

    The Concrete CMS REST API lists groups at GET /ccm/api/1.0/groups. In versions 9.2.0 through 9.5.2, the method behind that endpoint, listGroups() in Groups.php, registered a permission checker callback that returned true no matter what. The view permissions on individual groups never applied to the list.

    Any authenticated user whose API token carried the groups:read scope could call the endpoint and get back every group on the site, including groups they had no permission to view. The CVE record describes what that exposes as the organization's group structure, roles, and access hierarchy.

    I reported it to the Concrete CMS security team. They rated it 6.0 under CVSS 4.0, with a high confidentiality impact and a low privilege requirement, and the fix shipped in 9.5.3.

  • MDEV-39762

    A size check that wrapped around

    MariaDB replicas can receive compressed query events from their primary. To uncompress one, the replica reads a 32-bit length from the event header, works with it as a 64-bit value, and then casts the result back to 32 bits to decide where the data goes. Small results go into a fixed 4 KB buffer on the stack. Larger ones get a heap allocation.

    If the length in the header is close to the 32-bit maximum, the cast wraps it around to a small number. The replica then picks the stack buffer for data far larger than 4 KB, and its IO thread crashes.

    A normal primary cannot produce an event like that, so this needs a malicious or compromised primary, or a tampered replication stream. The ticket includes a test that reproduces the crash on a debug build. MariaDB fixed it in 10.11.19, 11.4.13, 11.8.9 and 12.3.3, released August 24, 2026, and in 13.0.2.