KINGSLEY OLUKANNI
Security Researcher | Application Security Engineer
Calgary, Alberta, Canada (remote-ready) • kingsley@securva.net • github.com/babakizo420 • babakizo.com
Summary
I find the bugs that patches leave behind. My work is incomplete-fix and variant analysis: I read a project's own security patch, and its fork history, and I find the residual the fix did not reach. That has earned me three published CVEs, a High-severity Incus advisory (8.5) published by the project's creator, and an accepted advisory at IBM's MCP Gateway, in software people run in production. I focus on MCP and AI-agent security, and I am an Immunefi-cleared smart-contract auditor. I do not stop at a theory; I reproduce every finding against the real software and hand the maintainer a working fix.
Published CVEs & Security Advisories
CVE-2026-55667 / File BrowserHIGH • CVSS 8.2
Authenticated out-of-scope file deletion via symlink-following RemoveAll; incomplete-fix of CVE-2026-54094 (CWE-22 + CWE-59). Credited reporter.
GHSA-fmm7-x4gx-8jhr • NVD-published
CVE-2026-63131 / OpenBao (HashiCorp Vault fork)MODERATE • CVSS 6.0
Access-control bypass: a stricter deny policy skipped for LIST operations under a broader parent wildcard. Cross-fork discovery, the bug was fixed in Vault but still live in the OpenBao fork. Credited reporter.
GHSA-xp3c-3jw3-4vcr
CVE-2026-27761 / GiteaCredited
Vulnerability reported and fixed in the Gitea self-hosted Git service. Credited reporter.
IBM mcp-context-forge (MCP Gateway)Accepted by IBM
SSE gateway health-check follows redirects (incomplete-fix): SSRF plus auth-header credential forwarding in AI-agent infrastructure. Reported to IBM and accepted; fix in progress, credited reporter.
GHSA-3frw-wjxx-2p6m • public number pending patch
Incus (LXD family)HIGH • CVSS 8.5
Arbitrary host file read and write through the virtual-machine template path (CWE-22 + CWE-59); an incomplete-fix that reached the container driver but not the QEMU one. Published by the Incus maintainer; fixed in 2.47.3. Credited reporter.
GHSA-4qxq-p5hm-3q3p
Core Skills
Vulnerability Research & AppSec: source-code review, incomplete-fix / variant analysis, SSRF, credential forwarding, authentication / authorization bypass, path traversal, command injection, RCE, deserialization.
MCP / AI-Agent Security: agent credential-forwarding, MCP server auth-boundary and SSRF review, prompt injection. This is where most of my recent work sits.
Web3 / Smart Contracts: Solidity auditing, Foundry, Slither, Aderyn; Immunefi-cleared, with findings on dYdX and Polymarket.
Tooling & Stack: Burp Suite, Nuclei, Python, TypeScript, Go (read), Docker, Cloudflare, Git; built an autonomous multi-agent research and triage system.
Certifications: CompTIA Security+ (in progress).
Experience
Independent Security Researcher & Consultant2025 to Present
- Responsible disclosure and bug-bounty research across web2 and web3. The credited findings above are the output: three published CVEs (File Browser, Gitea, OpenBao), a published High advisory at Incus (8.5), and an accepted advisory at IBM.
- Specialize in incomplete-fix and variant hunting: reading a project's patch and its fork-history to find the residual or ported gap the original fix missed.
- Deliver MCP / AI-agent security reviews and data-protection (NDPA) compliance audits for software vendors and small businesses.
- Designed and built an autonomous multi-agent pipeline that continuously discovers, verifies, and triages vulnerability candidates.
Secure Full-Stack Engineering2025 to Present
Security-by-design website platform (Pejji)
- Built a full-stack website platform with security-by-design defaults: privacy / NDPA compliance, cookie consent, and secure data handling.
- Own the architecture, deployment (Cloudflare), and security posture end to end; shipped live production sites.
Links
GitHub: github.com/babakizo420 • Portfolio: babakizo.com • Advisories verifiable via the GHSA / CVE IDs above.