

Vansh Gupta
17 posts

@Vansh_95a
Hi, I’m Vansh, a 13-year-old student exploring web application security. I focus on learning through hands-on testing and responsible disclosure.






Hey @Hacker0x01 super disappointed. Reported a critical bug on a private program: full access to 73 storage containers, (RCE) entire company's candidate PII downloadable. Triaged valid. Fixed by the team (confirmed). Then 2 months later closed as N/A "third-party SDK issue." If the key is served from your domain, leaking your users' PII, and your team fixes it how is that N/A? Filed mediation but 6–7 months is a long wait. Can someone from the team take a look? Bug is genuinely worth your time.














