FikreSekhel is a research-driven technology company applying mathematics, formal methods, and computational science to complex problems in cybersecurity and bioinformatics.
We believe complex scientific and engineering problems should first be understood through rigorous mathematical models. Our research combines applied mathematics, computer science, formal reasoning, statistical methods, and artificial intelligence.
We transform this research into computational methods, software, technical intelligence, and technologies designed to produce measurable impact in high-complexity environments.
Learn more about FikreSekhel
Selected research demonstrating how applied mathematics, formal methods, computational analysis, and scientific experimentation are used to understand complex systems and transform technical findings into operational intelligence.
| ID | Research Case | Severity | Type | Status | Disclosure |
|---|---|---|---|---|---|
|
FR-2026-001
|
Non-canonical JWT acceptance leading to revocation and rate-limit bypass
A trust mismatch between verification and application-layer token handling can allow variant tokens to remain valid while revocation and policy checks rely on strict string comparison.
|
High | Authentication / Logic Flaw | Coordinated Disclosure | Report available on request |
|
FR-2026-002
|
RPC response spoofing via postMessage trust boundary violation
Browser messaging trust assumptions can break when response handling is not strongly bound to source, origin, and expected request lifecycle.
|
High | Client-side Trust Boundary | Publicly Discussed | Disclosure summary available |
|
FR-2026-003
|
AES-CBC malleability enabling privilege bit-flipping in application workflows
Encryption schemes without integrity guarantees can permit controlled ciphertext manipulation, resulting in altered protected values and unsafe application decisions.
|
Critical | Cryptographic Design Flaw | Research Complete | Private / pending publication |
Each research problem is translated into a formal or computational model, investigated through reproducible experiments, and evaluated against its scientific, technical, and operational consequences.
Our work combines mathematical modeling, formal methods, static and dynamic analysis, statistical reasoning, and computational experimentation. The methodology is adapted to each research domain, from software security and cryptographic systems to genomic data and biological computation.
Research outcomes are transformed into reproducible methods, technical reports, computational tools, software, and operational intelligence. This allows complex scientific findings to become practical technologies capable of supporting real-world decisions.
Selected vulnerability discoveries, security reports, and public acknowledgements from FikreSekhel and its founder, including earlier independent research published under the name Franciny Salles.
| Library / Product | Finding | Severity | CVE | Public Advisory / Reference |
|---|---|---|---|---|
|
@hiprax/crypto
Cryptographic library
|
Pre-authentication resource amplification
via unauthenticated KDF parameters
Attacker-controlled key derivation parameters in
the ciphertext header can cause excessive resource
consumption before ciphertext authentication,
creating a denial-of-service risk.
|
Moderate | Pending assignment | GHSA-fgpf-v2mm-vhx6 |
|
fast-jwt
JSON Web Token library
|
Cache key collisions causing identity
and authorization confusion
When caching is enabled with a collision-prone custom
cacheKeyBuilder, verification can return claims from
a different token, potentially causing impersonation
or privilege escalation. Default caching is unaffected.
|
Critical | CVE-2026-35039 |
GHSA-rp9m-7r4c-75qg
Reporter: Franciny Rojas (@fasrm)
|
|
fast-jwt
JSON Web Token library
|
Stateful regular expressions causing
inconsistent claim validation
Reusing regular expressions with /g or /y flags in
allowed-claim checks can cause the same valid token
to alternate between acceptance and rejection.
This can disrupt authentication and trigger retries.
The issue does not allow invalid tokens to be accepted.
Patched version: 6.2.1.
|
Moderate | CVE-2026-35040 |
GHSA-3j8v-cgw4-2g6q
Reporter: Franciny Rojas (@fasrm)
|
|
protobuf.js
Protocol Buffers library
|
Denial of service through unbounded
JSON descriptor recursion
Deeply nested, untrusted JSON descriptors processed
by Root.fromJSON() or Namespace.addJSON() can exhaust
the JavaScript call stack, causing descriptor loading
to fail or potentially crashing the process.
|
Moderate | CVE-2026-45740 |
GHSA-jggg-4jg4-v7c6
Reporter: Franciny Rojas (@fasrm)
|
|
multer
Multipart upload middleware
|
Denial of service through incomplete
cleanup of aborted uploads
Aborted or malformed multipart uploads can leave
orphaned partial files when diskStorage is used.
Repeated requests can accumulate these files,
exhaust disk space, and cause denial of service.
|
Moderate | CVE-2026-5038 |
GHSA-3p4h-7m6x-2hcm
Credited finder: Franciny Rojas (@fasrm)
|
|
ssh2
SSH client and server library for Node.js
|
Out-of-bounds write in the Windows Pageant helper
The report identified an unchecked copy in the native
Pageant helper, where an input length could exceed
a fixed-size shared-memory region. The maintainer
responded by removing Pageant support.
Resolution: affected functionality removed upstream.
|
Not rated | Not confirmed |
Issue #1498
Reporter: Franciny Rojas (@fasrm)
|
|
Axios
HTTP client for JavaScript
|
Custom credential headers forwarded
across cross-origin redirects
The report demonstrates that custom secret-bearing
headers can be forwarded to a different origin during
redirects, even when the standard Authorization header
is removed. It proposes configurable handling of
sensitive headers.
Public hardening report; maintainer validation
has not been confirmed.
|
Not rated | Not confirmed |
Issue #10711
Reporter: Franciny Rojas (@fasrm)
|
|
Ponytail
Python benchmark component
|
Unrestricted URI scheme handling
in benchmark-local.py
The --ollama-url argument reaches urllib.request.urlopen()
without scheme validation, allowing schemes such as
file:// and FTP. The maintainer acknowledged the report
and agreed that an HTTP/HTTPS allowlist was appropriate.
No practical remote code execution or data exfiltration
was demonstrated. The public issue is closed.
|
Not rated | Not confirmed |
Issue #166
Reporter: Franciny Rojas (@fasrm)
|
|
WampServer
Web development environment
|
Cross-site scripting in index.php
A cross-site scripting vulnerability in the index.php
localhost page, credited to Franciny Salles in the
vendor changelog. The fix is documented in the
WampServer 3.1.5 release notes.
|
Medium
NVD CVSS 3.0: 6.1
|
CVE-2018-1000848 |
Vendor changelog
Credited researcher: Franciny Salles
|
Severity labels follow the referenced GitHub advisories or the identified NVD assessment. "Not rated" indicates that no formal severity rating is documented here. "Not confirmed" indicates that a CVE identifier has not been verified for that entry. Public reports are distinguished from confirmed advisories in their descriptions.
Work with FikreSekhel to transform complex scientific and engineering problems into mathematical models, computational methods, and practical technologies.