Early access: the directory is still filling out, and every rating here is a reported experience.

Researcher profile

Maliq Barnard
Maliq Barnard ✓ verified
@sahwe · member since August 2026
Verified researcher Multi-platform Contributor Early member
Verified Crew
BugScore
64/100
Established

Credibility earned elsewhere: verified platform standing, vendor-confirmed credits and reviewed evidence.

Contribution
24/100

What you’ve added here: reviews written, and how useful others found them.

Awarded CVEs 3

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

GitHub advisory ·pip

Arbitrary file write via path traversal in -u username / -U userfile output filename

GitHub advisory

Zen Browser MAR updater ships with signature verification removed — unsigned updates accepted

GitHub advisory
How this BugScore is built
Platform standing 26.5/40
Drawn straight from your verified HackerOne profile. The percentiles are HackerOne’s own, not ours.
HackerOne signal percentile 12.2/20
HackerOne ranks your report signal above 61% of their researchers: their own population-wide measure, used as-is.
HackerOne impact percentile 9.8/12
Your reported impact sits in the 82nd percentile on HackerOne.
HackerOne reputation 4.5/8
Your HackerOne reputation is 174, scored on a log scale so sheer volume cannot dominate the number.
Vendor-confirmed credit 27.1/30
You hold 5 verified vendor credits, 2 verified CVEs you added yourself, and 7 HackerOne thank-yous. Credits count most, with diminishing returns as they add up.
Moderator-verified evidence 0/20
You have no moderator-verified private evidence. Private, NDA’d, or direct-to-vendor work can be verified here without going public.
Verification breadth 10/10
You have verified 2 platform accounts: breadth of proof across programs.
Penalties 0-10
No HackerOne warnings and no upheld disputes count against you.

BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. It is a signal to weigh, not a warranty.

How this Contribution is built
Reviews written 12/40
You’ve written 3 program reviews.
Helpful votes received 2/25
Other members marked your reviews helpful 2 times.
Programs covered 9/15
You’ve reviewed 3 distinct programs.
Balanced reviewing 0/10
Post both positive and critical reviews to show you call it as you see it.
Tenure 1/10
You’ve been a member for 1 month.

Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.

Verified platform accounts · portable reputation
HackerOne · sahwe
174Reputation
#9,696Rank
1.09Signal
17Impact
6Badges
0Disclosed
GitHub · smoke-wolf
Thanked by 5 programs

Programs that have publicly thanked this researcher on HackerOne, with the reputation earned in each.

MongoDB HackerOne rank #76 44 rep
Malwarebytes HackerOne 32 rep
Moneybird HackerOne 22 rep
USPS - United States Postal Service HackerOne rank #31 7 rep
CLEAR HackerOne rank #79 0 rep
Security-release credits
Credited by Apple ×5
Additional recognition macOS Golden Gate 27 CoreBluetooth - LE BR2026-0000-013202 ✓ claimed vendor credited Maliq Barnard
Additional recognition tvOS 27 CoreBluetooth - LE BR2026-0000-014176 ✓ claimed vendor credited Maliq Barnard
Additional recognition iOS 27 and iPadOS 27 CoreBluetooth - LE BR2026-0000-012498 ✓ claimed vendor credited Maliq Barnard
Additional recognition macOS Tahoe 26.5 Security BR2026-0000-009457 ✓ claimed vendor credited Maliq Barnard
Additional recognition macOS Tahoe 26.6 RemoteServiceDiscovery BR2026-0000-001186 ✓ claimed vendor credited Maliq Barnard
GitHub advisory credits

GitHub security advisories crediting the verified GitHub account smoke-wolf. GitHub credits an account, not a name, so these are an exact match to a login Maliq Barnard has proved they control. There is no claim to make and nothing to dispute.

GHSA-j657-m4c4-24jq ↗ · CVE-2026-59224 pip Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection) high 2026-07-24 · reporter
GHSA-rp68-wfv6-3cq3 ↗ · CVE-2026-42866 Arbitrary file write via path traversal in -u username / -U userfile output filename high 2026-04-24 · reporter
GHSA-qpj9-m8jc-mw6q ↗ · CVE-2026-41431 Zen Browser MAR updater ships with signature verification removed — unsigned updates accepted high 2026-04-24 · reporter
BugBadge · portable credential
BR-RSNN-9W25

Maliq Barnard can attach a fresh, time-limited attestation of this badge to a report on any platform. It attests track record: never a legal identity, and never a guarantee.

View badge
3
Reviews written
3
Programs reviewed
13
Reports represented
2
Helpful votes
How they review
3.3 avg rating given
1 positive 2 mixed 0 negative
Where they hunt
Direct / email 1
Bugcrowd 1
HackerOne 1

Programs reviewed

3

Reviews

National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
I submitted 3 SSRF findings across the NASA VRP scope - they all went informative
neutral

As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs and vendors.

via Bugcrowd reports 3 1st reply Within 3 days resubmit yes
Maliq Barnard ✓ verified · Aug 3, 2026 · Share ↗ 0 helpful
Apple Security Bounty
Responsive, fair, and quick.
positive

I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.

via Direct / email reports 9 paid $500 – $2k 1st reply Within 3 days resubmit yes recommends yes skill Advanced
Maliq Barnard ✓ verified · Aug 3, 2026 · Share ↗ 2 helpful
MongoDB Bug Bounty
One click remote code execution - Working as intended. Then reopened
neutral

Triage overall left me relatively disappointed, but by equal measures, relived. I reported a remote code execution to this program in May, the H1 analyst team reviewed and downgraded the severity from critical to high on account of double-counting the UI:R component, in the CVSS. Two weeks after the report was closed as informative quote: "The team has confirmed that the current behavior is working as expected given the trust model of the application." After thorough, and repeated follow up and technical rebuttal the company corrected their initial decision and awarded a bounty payout. The timeline on this report was May 23 → July 9, a whole 47 days, with 27 of those days, it sitting as Informative. Ultimately their turnaround and decision to award the bounty was appreciated and I will continue to engage with them where appropriate. However, to any new researchers on H1, do not pursue this program before you have the signal to request mediation, as without it, you will be entirely at the mercy of the program.

via HackerOne reports 1 paid $2k – $10k 1st reply Within 3 days resubmit yes recommends no skill Advanced
Maliq Barnard ✓ verified · Aug 11, 2026 · Share ↗ 0 helpful