$ whoami▊
João Víctor
Security researcher. I break things and write about it — CVEs, vulnerability research, and offensive security notes.
## 01. about
I started breaking things at fourteen, web hacking basics, mostly — and that curiosity pulled me into programming, by fifteen I was working professionally as a web developer, and I never left: I have spent years inside large multinational companies, shipping software in global environments with strict security and compliance requirements.
Today I work as a tech lead, and that builder's background shapes how I do security: application security, reverse engineering, and vulnerability research across different languages and stacks — reading code the way the people who wrote it do, then finding where it fails. This site is where the writeups land.
## 02. skills
[security]
- > AppSec — implementing SAST and DAST pipelines, code review, threat modeling, and secure design, shaped by years shipping software under global compliance requirements.
- > Vulnerability research — finding and reporting bugs across different languages and stacks, the target picks the toolchain, not the other way around.
- > Reverse engineering — taking apart binaries and undocumented systems to understand how they actually behave.
- > Pentesting — web and application-focused offensive testing, from recon to reproducible, reported findings.
[engineering]
- > TypeScript / JavaScript — my professional languages since day one, product code, security tooling, and exploits alike.
- > React — years of production apps at scale; now leading teams that build them.
- > Node.js / NestJS — designing and shipping production backend services and APIs, TypeScript on both sides of the stack.
- > Python — scripting, automation, and tooling,from security research to production services.
- > Java — enterprise backends in multinational environments, and a frequent target when auditing.
- > PHP — production web backends, from legacy monoliths to modern stacks.
- > Leadership — leading global engineering teams, turning roadmaps into value delivered to stakeholders.
- > CI/CD — building and maintaining pipelines for production software, security tooling, and research automation.
- > Cloud — AWS, GCP, and Azure, designing and shipping production services in the cloud.
- > Kubernetes & Docker — containerized production services, from local development to global deployments.
[ai]
- > AI & LLMs — applying models to security workflows — triage, tooling, code analysis, and studying where AI systems themselves break.
- > Claude Code — currently running automated vulnerability research campaigns, agentic workflows that map attack surface, generate hypotheses, and validate findings end to end.
## 03. exploits
> Jul 28, 2026
CVE-2026-40901: DataEase 4-bug chain to unauthenticated root RCE
Auth bypass → JDBC blocklist bypass → stacked-query SQLi → Java deserialization in a Quartz job-store BLOB. Four modest bugs in DataEase ≤ v2.10.20 compose into remote code execution as root, with a dockerized lab and a working PoC.
[cve][rce][dataease][deserialization][sqli][poc]
> Jul 25, 2026
CVE-2026-26216: Crawl4AI unauthenticated RCE via hooks
A single unauthenticated JSON POST to Crawl4AI's /crawl endpoint executes Python as root — the homemade builtins sandbox kept __import__ on the allowlist. Dockerized lab plus a stdlib-only exploit.
[cve][rce][crawl4ai][sandbox-escape][poc]
> Jul 20, 2026
CVE-2026-63030: wp2shell — WordPress Core pre-auth REST route confusion → SQLi
A dockerized lab for wp2shell: a REST batch route-confusion bug in WordPress Core 7.0.1 chained with an author__not_in SQL injection to leak user password hashes with zero credentials, driven by a dependency-free Python exploit.
[cve][wordpress][sqli][rce][poc]
## 04. recent writeups
→ view all posts## 05. contact
- github: github.com
- linkedin: linkedin.com
- email: send an email