All authors

Amirmohammad Safari

Security Researcher

Part-time bug hunter, full-time thinker of thoughts nobody asked for.

— Posts 05 / 05
  1. 2026 · 02 · 10

    When Two Parsers Disagree: Exploiting Query String Differentials for XSS

  2. 2026 · 02 · 03

    Shaking the MCP Tree: a security deep dive

  3. 2025 · 10 · 19

    Cloudflare Image Proxy as a CSPT Gadget: A Cross-Origin CSPT Exploit

  4. 2025 · 06 · 01

    Puny-Code, 0-Click Account Takeover

  5. 2025 · 02 · 15

    CSS Data Exfiltration to Steal OAuth Token