Lykrin / independent security researcher

Source code review.
Reverse engineering.

I investigate application internals, trace trust boundaries, and document practical fixes. Explore the specialties below and the research that demonstrates them.

Read the research
Specialties

Areas of expertise

Concrete capabilities, connected to the work that demonstrates them.

The research notebook

Research journal

Grouped by specialty. Newest work first within each area.

22 articles

Application security & source code review

9 articles
Source review

SSH adapters and remote shell boundaries

Python → SSH → container → sh -c: avoiding a local shell does not stop the remote shells parsing. Found unquoted inner-shell operands and a validator that accepts a trailing newline; proposes per-argument quoting and full-string matching.

30 September 2026Source findings
Request authority

Glance configuration controls a privileged network client

Glance v0.8.6 SSRF: response-supplied URLs and same-host redirects let widget requests reach other services and routes. A loopback Go probe shows both; fixed identifiers and route policy close them.

30 September 2026Source review and local probe
Browser content boundary

Where Glance API strings acquire markup authority

Glance v0.8.6 custom API widgets: nine experiments show where trusted-HTML and trusted-URL conversions turn API strings into active markup. Template diffs remove the unnecessary trust assertions.

30 September 2026Source review and local probe
Application boundaries

A gateway restart without a general root-control API

Rust/Axum: a restart button without mounting the Docker socket. Proxy identity is trusted only from the real peer address, and a root helper exposes just status and restart for one fixed target, behind a lock and cooldown.

6 September 2026Source review
Integrity and transaction boundaries

A self-merge deleted the record it should preserve

SQLite: merging a record into itself deleted it, and a late failure left half-copied associations. Identical IDs are now rejected at the API and store, and the whole merge runs in one transaction.

5 September 2026Remediated
Integrity review

Closing a failed transaction before the next caller uses it

SQLite: a failed snapshot replacement left the shared connection mid-transaction, so the next caller's writes joined it. Explicit rollback before re-raising restores the old snapshot and a clean connection.

2 July 2026Remediated
Integrity review

Preserving manual ownership during an automatic rebuild

An automatic rebuild kept user-edited groups but deleted their lineage edges. Cleanup now removes only edges it owns at both endpoints, and the regression test can no longer pass on empty output.

21 June 2026Remediated
Input and storage boundaries

Remove database-path authority from browser settings

FastAPI settings endpoint accepted db_path, so any API caller could choose the database location for the next start. Removed the field, rejected unknown fields, and moved the demo database out of a predictable shared temp path.

14 June 2026Remediated
Security review

Browser-origin checks across HTTP and WebSocket entry points

CSRF and cross-site WebSocket hijacking on a local web app: Origin-versus-Host checks on every mutating route and the WebSocket handshake, with the remaining scheme and missing-Origin gaps documented.

12 June 2026Remediated

Identity & authorization

4 articles
Identity policy

Authentik discovery is not a client's grant allowlist

Authentik 2026.8.3: OIDC discovery advertises a fixed grant list, but enforcement reads each provider's stored config. A disabled flow can still be listed, and a supported one can be missing.

26 September 2026Source analysis
Identity architecture

Native identity, local fallback, and narrow API exceptions

Paperless-ngx and FreshRSS: native OIDC, local fallback login and API credentials are separate entry points. Disabling automatic social signup does not forbid social signup; API exceptions keep application authentication.

26 September 2026Policy review
Identity policy

Forgejo enrollment: OpenID is not OpenID Connect

Forgejo v15.0.9: ENABLE_OPENID_SIGNUP governs legacy OpenID, not OIDC. Whether an external identity can create an account depends on separate OAuth2 settings, traced handler by handler.

26 September 2026Source analysis
Control-plane authorization

Authorize the VPN target before invoking its backend

Flask VPN control plane: once backend names entered mutation URLs, authentication alone would let an isolated-plane user POST against the trusted plane. Per-plane membership checks now run before any privileged add or revoke.

5 July 2026Source review

Infrastructure security

7 articles
Infrastructure review

Closing an intake's outbound trust-boundary gap

nftables egress: a sandboxed intake guest with locked-down ingress could still open TCP connections to protected internal hosts. A default-drop output policy blocked them; health checks and proxy traffic kept working.

26 September 2026Remediated
Infrastructure review

Glance: TLS, redirects, and the browser boundary

Glance v0.8.6: eight widget fetches had TLS certificate verification disabled. Removed all eight, then traced API credentials through redirects and templates with a loopback Go probe comparing Authorization and x-api-key handling.

26 September 2026Remediated
Key and recovery boundaries

Encrypted backups need a key path that survives the outage

Proxmox Backup Server client-side encryption: the documented protected key replica could not be retrieved. Recreated it, proved it matched the live key, and decrypted a real restore whose checksum matched the source.

26 September 2026Remediated
Policy and trust-boundary review

Closing the direct-backend route around a login gateway

Forward auth only protects traffic that passes through the proxy. Source-specific nftables permits and drops close the direct route to backend listeners while keeping named health checks.

31 August 2026Implemented policy
Authorization policy review

Turning MQTT credentials into per-role topic boundaries

Shared MQTT broker: authentication alone did not limit which topics a client could use. A per-role ACL confines each client to its namespace; wildcard and integration exceptions are called out.

31 August 2026Implemented policy
Patch analysis

VPN revocation and rollback state

WireGuard peer revocation touches four stores. Reconstructs a July fix and its ordering test, and shows how rolling back after a bookkeeping failure can restore a peer that was already revoked.

5 July 2026Source review

Desktop application security

2 articles
Third-party desktop security

BDO Companion: pipe authorization, UIAccess, and signing

BDO Companion 0.7.3 (Windows): static review of the overlay's named-pipe security, its UIAccess manifest request, and embedded signing material versus verified trust. Nothing was executed.

30 September 2026Source review
Desktop authentication

Hyprlock: separate authentication from reader cleanup

Hyprlock v0.9.6: blocking fprintd calls stalled the Wayland event loop, and a fingerprint unlock could log a failed PAM attempt. A local patch moves device work off the event loop without loosening authentication.

20 September 2026Local patch
About

Lykrin

GitHub profile

I study application internals, review code, and trace requests across authentication, data, and privilege boundaries. My work turns unsafe behavior into practical fixes: tighter capabilities, explicit authorization, atomic updates, and verified transport.

Here I share what I learn from systems I operate, with source-level explanations, working examples, and patch patterns other developers can use.

Research repositories: Homelab security · Application security · Desktop security.

Found an error in an article or a vulnerability in my code? Report it privately through GitHub security advisories.