Adel Assakaf عادل السقاف
Software Engineer, Security Researcher
Software engineer with a strong mathematics background (two MSc in probability and cryptology) and a focus on security.
I build back-end systems and security tooling. Currently, I develop AI-driven scanners and attack-surface infrastructure at Escape (YC W23), in Go, Python, and TypeScript.
Alongside engineering, I do independent vulnerability research. I've found and responsibly disclosed multiple high- and critical-severity flaws in widely used open-source projects, including a HIGH-severity prototype pollution vulnerability in n8n (CVE-2026-59206). I also contribute to open-source security tooling (httpx / ProjectDiscovery).
I'm drawn to hard technical problems at the intersection of systems, security, and mathematics, from low-level code analysis to applying ML to security.
Focus
Published research
- Prototype Pollution to Unauthenticated User Enumeration in n8n (CVE-2026-59206)
- Privilege Escalation to Superuser in Paperless-ngx (GHSA-59xh-5vwx-4c4q)
- Contribution to ProjectDiscovery's httpx (PR #2393)
- Contribution to Turbot's Steampipe (Google Workspace) (PR #88)