Skip to content
View 7acini's full-sized avatar
👨‍💻
Pwning and Coding
👨‍💻
Pwning and Coding

Block or report 7acini

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
7acini/README.md

Guilherme Facini

Founder @ Kuro Security · Application Security Analyst · Software Developer

I build applications, investigate how they break, and turn findings into fixes.

Kuro Security LinkedIn Email


About me

I'm a software developer and application security analyst from Brazil, and the founder of Kuro Security.

My work connects software development with offensive security: reading code, testing assumptions, reproducing vulnerabilities, and helping developers address their root causes.

I'm especially interested in authorization flaws, business logic vulnerabilities, and the gap between how an application is designed and how it actually behaves.

  • Application security: web and API testing, secure code review, and remediation.
  • Security research: vulnerability analysis, reproducible proofs of concept, and responsible disclosure.
  • Software development: building applications and practical security tools.
  • DevSecOps: bringing security into development workflows and Linux environments.

Kuro Security

At Kuro Security, I work on pentesting, Red Team, and AppSec, with a focus on clear evidence, practical impact, and actionable remediation.

A falha já existe. A gente chega antes.

Explore Kuro Security →

Security research

Original research

CVE-2026-102261 — Camaleon CMS authorization bypass

I identified an authorization flaw in the media crop workflow that allowed an authenticated user with media management permissions to modify another user's avatar through the saved_avatar parameter.

The repository includes a non-destructive checker for the authorization control introduced in version 2.9.3.

Selected PoCs

Reproductions and technical explorations of publicly disclosed vulnerabilities. Original discovery credit belongs to the respective researchers.

Repository Focus
CVE-2025-2304 Camaleon CMS vulnerability PoC
CVE-2024-41570 Havoc C2 SSRF PoC

Security tools

Project What it does
minimal-waf An HTTP reverse proxy written in Go that inspects requests, with monitoring and blocking modes.

Open source

  • Omakub — Contributions to the Ubuntu development environment setup.
  • br-acc — Open data and technology for making Brazilian public information more accessible.

Let's connect

For AppSec work, security research, or open-source collaboration:

Kuro Security · LinkedIn · 7acini@gmail.com

Pinned Loading

  1. CVE-2026-102261 CVE-2026-102261 Public

    https://vuldb.com/cve/CVE-2026-102261

    Go