Skip to content
View kai63001's full-sized avatar
🟦
𝐰𝐚𝐭𝐜𝐡𝐢𝐧𝐠 𝐭𝐡𝐞 𝐰𝐨𝐫𝐥𝐝 𝐠𝐨 𝐪𝐮𝐢𝐞𝐭.
🟦
𝐰𝐚𝐭𝐜𝐡𝐢𝐧𝐠 𝐭𝐡𝐞 𝐰𝐨𝐫𝐥𝐝 𝐠𝐨 𝐪𝐮𝐢𝐞𝐭.

Highlights

  • Pro

Block or report kai63001

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kai63001/README.md

Supanat Konprom

Product engineer · Application security researcher
I ship native, mobile, and web products — and I take apart other people's.

korsund.com

App Store · Google Play


What I do

Two disciplines, one habit: read the system until it gives up its assumptions.

Building — native desktop in Rust, iOS and watchOS in Swift, cross-platform in Flutter, web in TypeScript. I own the whole line: interface, API, data model, deployment, and the App Store review that follows.

Breaking — authentication, authorization, business logic, API surface, and data exposure. Everything goes through responsible disclosure, and I hold details until the vendor ships a fix.


Shipped

Product Platform What it is
Zolt macOS · Windows · Linux GPU-rendered database client written in Rust on GPUI. 120 fps across Postgres, MySQL, SQLite, Redis, and MongoDB — no Electron.
Trade Buddy Web · iOS Trading journal with a visual PnL calendar, AI coaching, and decision-grade performance analytics.
Korva Desktop Offline Microsoft Publisher alternative that opens real .pub files and exports print-ready PDF.

Security research

CVE-2026-45490

Microsoft .NET SDK — elevation of privilege to SYSTEM

CVSS 7.8 High

CWE-285 · .NET SDK 8.0 · 9.0 · 10.0 · Windows · Elevation of privilege

The dotnet workload command exposes a named pipe with a weak ACL. Any local user can drive that pipe to create or truncate arbitrary files as another local user — including a privileged one — turning a low-privilege foothold into full SYSTEM control.

Fixed in the June 2026 servicing release: SDK 10.0.109, 9.0.118, 8.0.128 and later.

MSRC advisory · CVE record

Published records

Fourteen more records across the WordPress ecosystem, sorted by CVSS base score.

CVE CVSS Product Class
CVE-2026-7458 🔴 9.8 Critical User Verification Authentication bypass
CVE-2026-57739 🔴 9.3 Critical AcyMailing SMTP Newsletter Blind SQL injection
CVE-2026-42747 🔴 9.3 Critical Easy Form Builder Blind SQL injection
CVE-2026-7465 🟠 8.8 High Spectra Gutenberg Blocks Remote code execution
CVE-2026-48874 🟠 8.5 High GamiPress SQL injection
CVE-2026-3453 🟠 8.1 High ProfilePress Subscription IDOR
CVE-2026-3629 🟠 8.1 High Import and export users Privilege escalation
CVE-2026-49112 🟠 7.5 High Shared Files Path traversal
CVE-2026-3454 🟡 6.5 Medium GenerateBlocks Sensitive data exposure
CVE-2026-48965 🟡 6.5 Medium XCloner Sensitive data exposure
CVE-2026-3722 🟡 6.4 Medium Auto Image Attributes Stored XSS
CVE-2026-3361 🟡 6.4 Medium WP Store Locator Stored XSS
CVE-2026-3369 🟡 5.4 Medium Better Find and Replace Stored XSS
CVE-2026-4664 🟡 5.3 Medium Customer Reviews for WooCommerce Authentication bypass

Combined reach of the affected WordPress plugins is over 1.6 million active installs, with a single record — Spectra — covering 1M+ on its own.

Not public yet

Target Status
NoMachine Private research, details withheld
Foxit PDF Private research, details withheld
Additional vendors In the disclosure queue

Details go public when the vendor ships, not before.


Stack

Languages — Rust · Swift · Dart · TypeScript · Go · PHP · C# · Solidity
Native & mobile — GPUI · SwiftUI · watchOS · Flutter · Android
Web — Next.js · Nuxt · Svelte · Astro · Node.js · NestJS · Express
Data & infra — PostgreSQL · MongoDB · RabbitMQ · Google Pub/Sub · Docker · Nginx · Google Cloud · Cloudflare · Linux


Elsewhere

korsund.com — full portfolio and disclosure archive
App Store · Google Play — published apps

Open to security research collaboration and product work. Reach me at supanat0245@gmail.com.

Counts current as of July 2026.

Pinned Loading

  1. wildcard-game wildcard-game Public

    Wild game is NFT Card Game online make with godot or unity, dapp web3 (react,next js) marketplace (sell and buy NFT) and mint (create) NFT upload to IPFS

    C# 113 50

  2. unclelife unclelife Public

    Building UncleLife.co: A Deep Dive into Next.js, Supabase, and the Power of Notion Integration

    TypeScript

  3. focusify focusify Public

    Focusify.io is a productivity application designed to help you streamline your tasks, organize your notes, master the Pomodoro technique, and create a work environment that resonates with your pers…

    TypeScript 3

  4. peakpicks peakpicks Public

    AI-generated content engine with affiliate monetisation Rust (Actix + SurrealDB) · Next.js frontend

    TypeScript

  5. SummarizeIt SummarizeIt Public

    Instant text, video & audio summaries on iOS Flutter client · Python (llmlingua) & Node.js (Whisper) services · MongoDB · RevenueCat IAP

    Dart 2

  6. pgvector/pgvector-node pgvector/pgvector-node Public

    pgvector support for Node.js, Deno, and Bun (and TypeScript)

    JavaScript 442 22