Phat Mai
Security Researcher & Penetration Tester
Focusing on vulnerability analysis, source code review, and offensive security research.
Phat Mai — Security Researcher & Pentester
CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE
# CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE  ## Overview ...
Vulnerability Research (18 Articles)
Root cause analysis, CVE disclosures, and exploit mechanics.
CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE
# CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE  ## Overview ...
CVE-2026-3359 WordPress Form Maker by 10Web Plugin <= 1.15.42 is vulnerable to a high priority SQL Injection
# Critical SQL Injection (CVE-2026-3359) in WordPress Form Maker by 10Web  ## Overview Published: ...
CVE-2026-2628 WordPress All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability
# WordPress All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability  ## Overvie...
Focus Areas & Skills
Technical Focus & Domains
Core technical capabilities and research focus.
Vulnerability Research
Auditing open-source plugins, CMS extensions, and web applications, followed by responsible disclosure and patch analysis.
Source Code Review
Manual static code analysis across Java, PHP, Python, and JavaScript to identify source-to-sink data flows and unsafe patterns.
Java Deserialization
Studying Java object serialization vulnerabilities, gadget chains in popular libraries (Commons Collections), and ysoserial payloads.
Active Directory Assessment
Practicing internal infrastructure testing techniques including Kerberoasting, AS-REP Roasting, and domain privilege escalation.
Web Security Testing
Identifying and reproducing common web vulnerabilities such as SQL Injection, SSTI (Velocity/Thymeleaf), SSRF, and File Upload.
Technical Writeups
Documenting step-by-step reproducible methodology, technical analysis, and mitigation advice for researchers and developers.
Technical Writeups & Labs (31 Writeups)
Walkthroughs and notes from CTFs, security labs, and pentesting platforms.
Velocity Server Side Template Injection Challenge
# Velocity Server Side Template Injection Challenge ### Tổng quan về lab Velocity SSTI Đây là một lab mình thiết kế ra để demo và học về SSTI. Bên trong l...
Tryhackme Hammer challenge WriteUp
# TryHackMe Hammer Web Challenge WriteUp  ### Enumeration  là một thông điệp trong giao thức xác thực Kerberos. Đây ...
ServerSide Template Injection (SSTI) Lab
# ServerSide Template Injection (SSTI) Lab ### SSTI là gì Server-Side Template Injection (SSTI) là một lỗ hổng bảo mật web nghiêm trọng cho phép kẻ tấn cô...
GraphQL API Vulnerability
# GraphQL API Vulnerability PortSwigger Challenge ### Overview về GraphQL GraphQL là một ngôn ngữ truy vấn cho API (Query Language for APIs) và cũng là mộ...
PortSwigger CORS (Cross-Origin Resource Sharing) challenge WriteUp
# PortSwigger CORS (Cross-Origin Resource Sharing) challenge WriteUp ### Overview về CORS #### CORS là gì? Vì sao lại xuất hiện - CORS (Cross-Origin Reso...
Publication Cadence
Release timeline and article cadence across recent months.