KINGSLEY OLUKANNI

Security Researcher  |  Application Security Engineer
Calgary, Alberta, Canada (remote-ready)  •  kingsley@securva.net  •  github.com/babakizo420  •  babakizo.com

Summary

I find the bugs that patches leave behind. My work is incomplete-fix and variant analysis: I read a project's own security patch, and its fork history, and I find the residual the fix did not reach. That has earned me three published CVEs and a High-severity Incus advisory (8.5) published by the project's creator, in software people run in production. I focus on MCP and AI-agent security, and I am an Immunefi-cleared smart-contract auditor. I do not stop at a theory; I reproduce every finding against the real software and hand the maintainer a working fix.

Published CVEs & Security Advisories

CVE-2026-55667 / File BrowserHIGH • CVSS 8.2
Authenticated out-of-scope file deletion via symlink-following RemoveAll; incomplete-fix of CVE-2026-54094 (CWE-22 + CWE-59). Credited reporter.
GHSA-fmm7-x4gx-8jhr • NVD-published
CVE-2026-63131 / OpenBao (HashiCorp Vault fork)MODERATE • CVSS 6.0
Access-control bypass: a stricter deny policy skipped for LIST operations under a broader parent wildcard. Cross-fork discovery, the bug was fixed in Vault but still live in the OpenBao fork. Credited reporter.
GHSA-xp3c-3jw3-4vcr
CVE-2026-27761 / GiteaMODERATE • CVSS 4.3
API access-token scope-enforcement bypass: a non-repository-scoped token could read any private repository's commit data (commit messages, committer identity) via the RSS/Atom feed endpoints (CWE-863). Credited reporter.
GHSA-3pww-vcvm-3gmj
Incus (LXD family)HIGH • CVSS 8.5
Arbitrary host file read and write through the virtual-machine template path (CWE-22 + CWE-59); an incomplete-fix that reached the container driver but not the QEMU one. Published by the Incus maintainer; fixed in 2.47.3. Credited reporter.
GHSA-4qxq-p5hm-3q3p

Core Skills

Vulnerability Research & AppSec: source-code review, incomplete-fix / variant analysis, SSRF, credential forwarding, authentication / authorization bypass, path traversal, command injection, RCE, deserialization.
MCP / AI-Agent Security: agent credential-forwarding, MCP server auth-boundary and SSRF review, prompt injection. This is where most of my recent work sits.
Web3 / Smart Contracts: Solidity auditing, Foundry, Slither, Aderyn; Immunefi-cleared, with findings on dYdX and Polymarket.
Tooling & Stack: Burp Suite, Nuclei, Python, TypeScript, Go (read), Docker, Cloudflare, Git; built an autonomous multi-agent research and triage system.
Certifications: CompTIA Security+ (in progress).

Experience

Independent Security Researcher & Consultant2025 to Present
Secure Full-Stack Engineering2025 to Present
Security-by-design website platform (Pejji)

Links