KINGSLEY OLUKANNI

Security Researcher  |  Application Security Engineer
Calgary, Alberta, Canada (remote-ready)  •  kingsley@securva.net  •  github.com/babakizo420  •  babakizo.com

Summary

I find the bugs that patches leave behind. My work is incomplete-fix and variant analysis: I read a project's own security patch, and its fork history, and I find the residual the fix did not reach. That has earned me three published CVEs and a High-severity flaw (CVSS 8.5) credited across both Canonical LXD and Incus, in software people run in production. I focus on MCP and AI-agent security, and I am an Immunefi-cleared smart-contract auditor. I do not stop at a theory; I reproduce every finding against the real software and hand the maintainer a working fix.

Published CVEs & Security Advisories

CVE-2026-55667 / File BrowserHIGH • CVSS 8.2
Authenticated out-of-scope file deletion via symlink-following RemoveAll; incomplete-fix of CVE-2026-54094 (CWE-22 + CWE-59). Credited reporter.
GHSA-fmm7-x4gx-8jhr • NVD-published
CVE-2026-63131 / OpenBao (HashiCorp Vault fork)MODERATE • CVSS 6.0
Access-control bypass: a stricter deny policy skipped for LIST operations under a broader parent wildcard. Cross-fork discovery, the bug was fixed in Vault but still live in the OpenBao fork. Credited reporter.
GHSA-xp3c-3jw3-4vcr
CVE-2026-27761 / GiteaMODERATE • CVSS 4.3
API access-token scope-enforcement bypass: a non-repository-scoped token could read any private repository's commit data (commit messages, committer identity) via the RSS/Atom feed endpoints (CWE-863). Credited reporter.
GHSA-3pww-vcvm-3gmj
CVE-2026-16033 / LXD (Canonical) and IncusHIGH • CVSS 8.5
Arbitrary host file read and write via the virtual-machine (QEMU) driver template path (CWE-22 + CWE-59); an incomplete-fix of CVE-2026-48752 that reached the LXC driver but not the QEMU one. The same flaw affects both sibling projects and was published and credited to me by Canonical (LXD, CVE-2026-16033) and by the Incus maintainer (CVE-2026-81497). Credited reporter.
CVE-2026-16033 • GHSA-9hcm-hxh5-7xxh (LXD) • CVE-2026-81497 • GHSA-4qxq-p5hm-3q3p (Incus)

Core Skills

Vulnerability Research & AppSec: source-code review, incomplete-fix / variant analysis, SSRF, credential forwarding, authentication / authorization bypass, path traversal, command injection, RCE, deserialization.
MCP / AI-Agent Security: agent credential-forwarding, MCP server auth-boundary and SSRF review, prompt injection. This is where most of my recent work sits.
Web3 / Smart Contracts: Solidity auditing, Foundry, Slither, Aderyn; Immunefi-cleared, with findings on dYdX and Polymarket.
Tooling & Stack: Burp Suite, Nuclei, Python, TypeScript, Go (read), Docker, Cloudflare, Git; built an autonomous multi-agent research and triage system.
Certifications: CompTIA Security+ (in progress).

Experience

Independent Security Researcher & Consultant2025 to Present
Secure Full-Stack Engineering2025 to Present
Security-by-design website platform (Pejji)

Links