Name: Manthan Ghasadiya
Class: Offensive Security Engineer / AI Security Researcher
Rank: S-Class (TryHackMe Top 1% Global)
Guild: Jacobian Engineering | Syracuse University (MS Cybersecurity, 3.84 GPA)
Specialization: Red Team Ops, AI/LLM & MCP Security, Vulnerability Research
Shadow Soldiers Deployed: 8-VM Red Team Lab (Proxmox)
Confirmed Kills: 4 published CVEs (up to CVSS 9.8) + 15 reported MCP vulns- 🗡️ Main Quest: Security Analyst @ Jacobian Engineering (web / mobile / cloud / API pentesting)
- 🔮 Special Ability: AI/LLM & MCP security research and exploitation
- ⚡ Power Level: Building offensive security tooling and automated testing frameworks
- 🛡️ Domain: manthanghasadiya.me
- 📚 Side Quests: GeeksNeuron (3.2K+) · HackyNerdz
Real, verifiable vulnerability research. Full technical writeups, root-cause analysis, and PoCs in my CVE writeups repo.
| CVE | Target | Severity | Class |
|---|---|---|---|
| CVE-2026-6942 | radare2-mcp | 9.8 CRITICAL |
RCE via shell escape |
| CVE-2026-42449 | n8n-mcp | 8.5 HIGH |
SSRF via IPv6 bypass |
| CVE-2026-35394 | mobile-mcp | 8.3 HIGH |
Prompt injection → Android intent |
| CVE-2026-47427 | github-mcp-server | 7.5 HIGH |
Nil-pointer DoS (pre-auth) |
Plus 15+ reported vulnerabilities across MCP SDKs and servers, with fixes merged upstream into Anthropic's official MCP Python SDK, TypeScript SDK, and servers.
mcpsec ·
pip install mcpsec· 10K+ PyPI downloads
The first open-source security scanner for live MCP servers. Sends real exploit payloads and confirms exploitation instead of guessing.
- scan - runtime exploitation against live servers
- fuzz - protocol fuzzing (600+ cases) for crash discovery
- audit - static analysis (149 Semgrep rules + tree-sitter AST) Every CVE above was found with it. Full list of discovered issues (with upstream links) is in the mcpsec README.
This Month Visitors
| 🎯 Achievement | 📊 Result |
|---|---|
| Published CVEs | 4 (up to CVSS 9.8) |
| National Cyber League | 77th / 8500 |
| TryHackMe Global | Top 1% |
| CNY Hackathon 2025 | 🥇 1st CTF · 🥉 3rd overall |
| NCAE CyberGames | 🥈 2nd + MVP |
| Graylog SIEM CTF (BSidesROC) | 🥈 2nd |
| sys_adm1ns CTF Team | 30th USA / 373 global |
| Red Team Homelab | 8-VM Proxmox (active) |





