Security training for the apps you actually ship. Open your browser and start hacking.
Léo Grambert · France
Web developer
& security researcher.
Currently exploring cybersecurity through vulnerability research, CTF competitions, and open-source security tools.
01 — Projects
Selected work
Loading contributions…
Threat intelligence platform: RSS aggregation, NVD CVE tracking, ENISA EUVD, databreaches, ...
This project aims to visualize hate crime data to bring visibility to crimes that are often invisible or normalized by society.
A fast, multi-threaded hash cracking tool written in Rust. This tool performs dictionary attacks against hashed passwords.
02 — CVEs
Vulnerabilities reported
CVE-2026-32255
Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch() server-side, and returns the full response body. An unauthenticated attacker can use this to make HTTP requests from the server to internal services, cloud metadata endpoints, or private network resources. This issue has been fixed in version 0.5.5. To workaround this issue, block or restrict access to /api/download/attatchment at the reverse proxy level (nginx, Cloudflare, etc.).
03 — Proof of concept
Public PoCs
- CVE-2026-32255 This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an open-source project management tool.
- CVE-2025-55182 This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell.
- CVE-2025-29927 This repository contains a POC and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
04 — Open source
Contributions
- usebruno/ bruno
Opensource IDE For Exploring and Testing API's (lightweight alternative to Postman/Insomnia)
- qazbnm456/ awesome-web-security
🐶 A curated list of Web Security materials and resources.
- kanbn/ kan
The open source Trello alternative.
- OWASP/ www-community
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
- OWASP/ www-project-vulnerable-web-applications-directory
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
05 — Writing
Publications
06 — Stack
Tools & technologies
- Programming Languages
- JavaScript, TypeScript, Python, PHP, Ruby
- Web Frameworks
- React, Next.js, Node.js, FastAPI, Ruby on Rails, Symfony, Hapi.js
- Security
- Vulnerability Research, CVE Analysis, CTF Challenges, Web Application Security
- DevOps & Tools
- Git, CI/CD, Docker, Linux, Shell Scripting
08 — Archive
Certificate archive
121 indexed
- Introduction to DevSecOps: Culture and Methodology May 2026
- Dive Into the World of Cyber Incident Detection and Response Apr 2026
- Protect your Connected Digital Systems by Following the 12 Best Practices from ANSSI Apr 2026
- Analyze and Manage IT Risks Mar 2026
- Everything You Need to Know About Computer Networks in Just a Few Hours Feb 2026
- Secure your Data with Cryptography Feb 2026
- Raise Cybersecurity Awareness Effectively Feb 2026
- Secure your Network with VPNs and Firewalls Feb 2026
- Conduct Your Cybersecurity Monitoring Feb 2026
- Discover the Basics of Digital Security Feb 2026
- Discover the World of Cybersecurity Feb 2026
- Try Hack Me - Advent of Cyber 2025 Dec 2025
- Try Hack Me - Security Engineer Sep 2025
- Try Hack Me - Web Fundamentals Feb 2025
- Try Hack Me - Jr Penetration Tester Jan 2025