Early access: the directory is still filling out, and every rating here is a reported experience.

Researcher profile

Pavan Nallamothu
Pavan Nallamothu ✓ verified
@pavanchow · member since August 2026

Security researcher and cloud/DevOps engineer. I break systems responsibly, and I build them to stay up. On the offensive side: 12 published CVEs, with fixes and credits from Apple, CISA, and the NSA, spanning web authentication, SSRF, broken access control, injection, and path traversal, including AI/ML agent frameworks like AutoGPT. On the engineering side: 4+ years building and operating AWS and on-prem infrastructure for a national education platform.

✓Verified researcher ◷Early member
BugScore
15/100
New

Credibility earned elsewhere: verified platform standing, vendor-confirmed credits and reviewed evidence.

Contribution
1/100

What you’ve added here: reviews written, and how useful others found them.

Awarded CVEs 1

An app may be able to read files outside of its sandbox

Security release ·Apple
How this BugScore is built
Platform standing 0/40
No verified HackerOne profile is linked, so there is no platform signal to read. This is the most defensible input we have. Link and verify HackerOne to earn it.
HackerOne signal percentile 0/20
HackerOne has not published a signal percentile for your account, so this earns nothing yet.
HackerOne impact percentile 0/12
HackerOne has not published an impact percentile for your account, so this earns nothing yet.
HackerOne reputation 0/8
HackerOne shows no reputation figure for your account yet.
Vendor-confirmed credit 9.4/30
You hold 1 verified vendor credit (1 CVE). Credits count most, with diminishing returns as they add up.
Moderator-verified evidence 0/20
You have no moderator-verified private evidence. Private, NDA’d, or direct-to-vendor work can be verified here without going public.
Verification breadth 6/10
You have verified one platform account. Verifying a second earns the rest.
Penalties 0-10
No HackerOne warnings and no upheld disputes count against you.

BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. It is a signal to weigh, not a warranty.

How this Contribution is built
Reviews written 0/40
You haven’t written any reviews yet.
Helpful votes received 0/25
Your reviews haven’t been marked helpful yet.
Programs covered 0/15
You haven’t reviewed a program yet.
Balanced reviewing 0/10
Post both positive and critical reviews to show you call it as you see it.
Tenure 1/10
You’ve been a member for 1 month.

Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.

Verified platform accounts · portable reputation
GitHub · pavanchow ✓
Security-release credits
Credited by Apple ×1
CVE-2026-43763 · An app may be able to read files outside of its sandbox macOS Sonoma 14.8.8 ATS BR2026-0000-004591 ✓ claimed vendor credited Pavan Nallamothu
BugBadge · portable credential
BR-9MR5-NDXD

Pavan Nallamothu can attach a fresh, time-limited attestation of this badge to a report on any platform. It attests track record: never a legal identity, and never a guarantee.

View badge
0
Reviews written
0
Programs reviewed
0
Reports represented
0
Helpful votes

Pavan Nallamothu hasn’t published any reviews yet.

Verified on GitHub. Reviews they write will carry extra weight.