Skip to content
View nakkouchtarek's full-sized avatar

Block or report nakkouchtarek

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nakkouchtarek/README.md

Typing SVG

Final-year master's student in cybersecurity focused on vulnerability research, exploit development, and offensive security.

Experience

  • Currently : Offensive Security Intern @ CIH Bank, Casablanca
  • DevSecOps Intern @ Evidence Way, Casablanca
  • Manager of Intern's Security Solution's Team @ Microtech Leaders, Chicago (Remote)
  • Cybersecurity Engineering Intern @ CIH Bank, Casablanca

Achievements & Rankings

2025

  • Microsoft MSRC Leaderboard Q3 2025: #60
  • Microsoft MSRC Leaderboard Q4 2025: #48
  • Google VRP Honorable Mention

Disclosed Vulnerabilities

Here are some of the disclosed vulnerabilities I found in my research :

VS Code & GitHub Copilot

Visual Studio

Grav CMS

Django

  • CVE-2026-1207: SQL Injection in RasterField Band Index Parameter

October CMS

Listmonk

  • CVE-2025-49136: Sprig Template Injection Leads to Environment Variable Disclosure

YesWiki

Metasploit Modules

Technical Writing

Connect

Pinned Loading

  1. CVE CVE Public

    This is a collection of Common Vulnerabilities and Exposures (CVEs) I discovered during security research and penetration testing activities on open source projects.