Het Patel
@networkshard
India
Inventyv Software Services Pvt. Ltd.
I'm a Cybersecurity Engineer - Intern focused on building defensive systems that are practical, scalable, and testable. I work across penetration testing, vulnerability validation, and secure engineering practices.
I specialize in Linux-first security workflows, web and infrastructure testing, and research-driven remediation while learning through hands-on delivery in real-world environments. My approach is simple: verify everything, automate what repeats, and keep systems understandable.
Skills & Tools
Hall of Fame
CERT-IN
Indian Computer Emergency Response Team
Hall of Fame — September & October 2025
View on CERT-IN →CVE
Arbitrary API Token Creation
InvenTree Security Advisory
Impact
Any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying the target's user ID in the user field of a POST /api/user/tokens/ request. The returned token is immediately usable for full API authentication as the target user, from any network location, with no further interaction required.
CVE ID
CVE-2026-35478
Score
8.3/10
Certifications
CRTA
Certified Red Team Analyst
Site Stats
249
21
2025