Skip to content
View the-vibe-dev's full-sized avatar

Block or report the-vibe-dev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
the-vibe-dev/README.md

Charles Vosburgh — Security Researcher, Linux Kernel Contributor, and Builder

I investigate how software crosses trust boundaries—and build tools that make security research more practical, accountable, and useful.

About me

I'm an independent, self-taught security researcher and developer. I learn by building, reading source, testing assumptions, and working with maintainers to turn findings into focused fixes.

My research spans authorization failures, sandbox escapes, parsers and deserialization, payment integrations, and kernel protocol and permission handling. I use AI-assisted development alongside hands-on source analysis and human review.

Security research

My public work includes 34 CVEs, 17 repository GitHub Security Advisories, and four accepted Linux mainline fixes. The CVE total includes two Linux kernel findings. My kernel contributions include two authored SCTP patches and two KSMBD findings credited through Reported-by, with nine verified stable backports across those fixes.

I've contributed research affecting projects including vm2, PyJWT, Apache Fory, TypeBox, isomorphic-git, fast-xml-parser, libheif, KEDA, and Yamcs, alongside WordPress plugins and payment integrations.

Portfolio What you'll find
CVE & GHSA research Published disclosures, root-cause analysis, affected versions, and remediation
Linux kernel contributions Accepted patches, reported findings, mainline commits, and stable backports

Projects I'm building

SecHive.ai

An operator-driven security research workbench for scoped investigations, evidence retention, reproducible analysis, and remediation review. I'm building it around deliberate scope and human-controlled disclosure decisions.

Explore SecHive.ai

GuardianNode

A local-first AI safety project for families, with a visible Windows agent, a parent-owned backend, local analysis, encrypted evidence storage, and a parent review dashboard. It's currently an alpha / developer preview built to support review and conversation, not replace human judgment.

Explore GuardianNode

More of my work

  • ThreatHive — defensive honeypot telemetry and controlled lab analysis; public alpha.
  • Dashburg — a local-first control center for agents, nodes, and AI infrastructure.

Connect

I'm interested in collaborating with maintainers, security researchers, and builders working on open-source security and practical tooling.

LinkedIn · Security research · Linux contributions · SecHive.ai

Public research totals updated October 2, 2026.

Pinned Loading

  1. fan-control fan-control Public

    A lightweight fan-control system for Dell PowerEdge servers running Proxmox. It collects GPU temperature data from a VM or host-side agent and uses iDRAC/IPMI commands to dynamically adjust server …

    Shell

  2. dashburg-public dashburg-public Public

    Dashburg is a local-first control center for running AI infrastructure. It orchestrates agents, manages nodes, launches terminals, and coordinates distributed AI workloads across your network.

    TypeScript

  3. guardiannode guardiannode Public

    GuardianNode is an early local-first AI safety monitor for families. It helps parents review risk signals from a child's Windows device using local screenshots/OCR/vision/text classification, a loc…

    Python

  4. threathive-public threathive-public Public

    ThreatHive is a public-alpha operator toolkit for defensive honeypot telemetry, fake-service lures, controlled lab analysis, public-safe reporting, and a local dashboard.

    Python

  5. CVE-GHSA CVE-GHSA Public

    Independent vulnerability research by Charles Vosburgh / the-vibe-dev — CVEs, GitHub Security Advisories, technical write-ups, root-cause analysis, remediation, and coordinated disclosure.

  6. Linux-Kernel Linux-Kernel Public

    Linux kernel contributions by Charles Vosburgh / the-vibe-dev — accepted mainline patches, security findings, upstream fixes, technical write-ups, and contribution history.