Two Input Paths, One Security Check: File Read in LookyLoo's PlaywrightCapture
How LookyLoo's document capture mode bypassed its own SSRF protections, and how the fix uses Playwright route handlers to filter secondary requests.

Jeroen Gui
Cybersecurity Professional
I find vulnerabilities in the tools defenders rely on, take down phishing at scale, and build security tooling. 12 advisories published and 10 CVEs assigned across MISP, PostgreSQL, Visual Studio Code, Wazuh and more.
Studying Computer Science & Information Management at KU Leuven. Based in Belgium.
10 assigned CVE IDs
Critical SQL injection in MISP
Through JustGuard
Automated abuse reporting
Source-code and black-box review of open-source security tooling. Findings reported through coordinated disclosure to MISP, PostgreSQL, Microsoft, Wazuh and others.
Advisories & CVEs →Detection pipelines, phishing-kit fingerprinting and automated abuse reporting, run in partnership with Quad9 DNS, the Global Signal Exchange, CleanDNS and Cloudflare.
JustGuard ↗Technical write-ups on the vulnerabilities I disclose, plus research on spam-filter evasion and how scammers abuse legitimate platforms.
Read the blog →How LookyLoo's document capture mode bypassed its own SSRF protections, and how the fix uses Playwright route handlers to filter secondary requests.
A look at how an incomplete fix from 2019 left MISP's auth key reset endpoint vulnerable to privilege escalation, and what the patch looks like.
How I found and reported a blind SQL injection in MISP's event and shadow attribute listing endpoints through unsanitized ordering parameters.