Independent web security research

Authentication. Authorization. Business logic. Tenant boundaries.

Breaking assumptions
at application boundaries.

I am Judel Palaca, also known as pal0x. I research practical vulnerabilities in modern web applications, with emphasis on identity, access control, cross-tenant isolation, and complex workflow abuse.

Manual-first testingCross-tenant reviewBusiness logic analysisClear reproduction
01 Profile

Security issues matter when they break a real trust boundary.

My work prioritizes realistic attack paths over noisy checklist findings. The objective is to understand how a system behaves, identify where its assumptions fail, and demonstrate impact in a controlled and reproducible way.

02 Core Areas

High-value application surfaces.

01 / IDENTITY

Authentication

Login, recovery, MFA, token lifecycle, session state, and identity verification paths.

02 / CONTROL

Authorization

Object access, privilege boundaries, role enforcement, tenant separation, and cross-account behavior.

03 / LOGIC

Business Logic

Workflow integrity, hidden state transitions, chained actions, and assumptions that fail under adversarial use.

03 Process

Manual exploration backed by code and evidence.

DISCOVER

Map the system

Inspect frontend behavior, API surfaces, account roles, state transitions, and feature boundaries before testing.

VALIDATE

Prove practical impact

Use controlled accounts and resources to verify exploitability without overstating severity or relying on assumptions.

REPORT

Make it reproducible

Deliver concise steps, clear evidence, impact analysis, and remediation guidance that engineering teams can act on.

04 Contributions

Selected security and engineering work.

Published security research and public contributions across real products and codebases.

High · CVSS 8.6GHSA-8mpm-q7mh-8fvhReporter: Judel777

Capgo CLI: symlink-following secret writes enabled arbitrary file overwrite and exposed credentials

Reported unsafe local secret writes in the Capgo CLI. Attacker-controlled repository symlinks could redirect writes to arbitrary files, while global build credentials were created with overly permissive file permissions. GitHub reviewed the advisory and lists affected versions before 7.84.6.

VIEW GITHUB ADVISORY →
Merged PRCode quality

Rapina

Cleaned singularize-related dead code warnings and aligned the change with feature-gated build requirements.

VIEW PULL REQUEST →
Merged PRConfiguration

AegisFlow

Added configurable max_body_size support and documented request-size controls.

VIEW PULL REQUEST →
Merged PRPerformance

SurfSense

Improved markdown rendering performance by lazy-loading syntax highlighting only when required.

VIEW PULL REQUEST →
Merged PRAccessibility

SurfSense

Added appropriate aria-label and aria-pressed behavior to improve the web search toggle for assistive technology.

VIEW PULL REQUEST →
05 Security Reviews

Focused reviews for modern web applications.

Controlled, limited-scope testing

I provide focused reviews for startups, SaaS applications, account systems, administrative panels, and sensitive workflows. Engagements are intentionally narrow and centered on realistic attack surfaces.

Authentication and account lifecycle
Authorization and tenant isolation
Invitation, file access, and privilege workflows
Business logic and chained exploitation paths
Contact channel

Discuss a controlled assessment.

Provide the application type, preferred scope, testing environment, and any important restrictions.