Skip to content
View zainnadeem786's full-sized avatar
🎯
Focusing
🎯
Focusing

Organizations

@ZN-Forge

Block or report zainnadeem786

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
zainnadeem786/README.md

Hi, I'm Zain Nadeem

Software Engineer & Security Researcher

Open Source Contributor • AI Builder

Building backend systems, local AI tools, security-focused software, and practical security tooling, with published vulnerability research and upstream open-source contributions.

Portfolio | Security Research | Open Source | LinkedIn

Based in Pakistan.

About

I build Python backend systems, APIs, and local-first AI tools with a practical security engineering focus. My core work spans Django, Django REST Framework, FastAPI, API development, local AI systems, and security automation. I also research framework and application-security issues, write technical analysis, and contribute bug fixes to mature open-source projects. The portfolio is the canonical hub for project writeups, research notes, and contribution history.

Security Research

Django REST Framework - CVE-2026-73228

  • Severity: Moderate
  • Reporter: Zain Nadeem (zainnadeem786)
  • DRF request.data parsing could bypass Django's configured DATA_UPLOAD_MAX_MEMORY_SIZE protection for JSON and URL-encoded request bodies.
  • Official advisory | Read technical analysis

Django REST Framework - CVE-2026-73229

  • Severity: Moderate
  • Reporter: Zain Nadeem (zainnadeem786)
  • AdminRenderer could disclose GET-protected data while rendering invalid write requests in specific permission and renderer configurations.
  • Official advisory | Read technical analysis

CyberChef - CVE-2026-72912

  • Severity: Moderate
  • Reporter: Zain Nadeem (zainnadeem786)
  • CyberChef's pretty-recipe parser could be forced into client-side CPU exhaustion through malformed #recipe= URL fragments.
  • Official advisory | Read technical analysis

Open Source Engineering

Selected public work with evidence:

Project Contribution evidence
CPython Selected merged bug fixes: #151779, #152223, #152471, #152906
CyberChef Multiple merged engineering and security-adjacent fixes: #2589, #2612, #2615, #2682
Celery Merged worker pidbox cleanup bug fix: #10363
Visual Studio Code Merged Workspace Trust transition fix: #328626
OWASP APTS Merged CI engineering contribution: #41
Django REST Framework Framework bug-fix PRs: #9977, #9981. Related maintainer-authored upstream security remediation: #10013
Nuclei Reported parser panic issue / bug research: #7524

View all contributions

Featured Projects

CodeGuardian AI

Privacy-first local secure code review platform for repository and ZIP scanning, Semgrep, Bandit, custom checks, context-aware finding reduction, local Ollama/Mistral analysis, and professional reporting.

Project page

SecOps AI

SOC investigation and log-analysis platform for log ingestion, detections, attack campaign correlation, risk scoring, timelines, cases, live ingestion, and local AI analyst context.

Project page

AI Brain

Portable local AI knowledge and engineering workstation for RAG, repository intelligence, trusted research, local security scanning, agentic coding, human approval, and Ollama-based workflows.

Project page

EchoMind AI

Status: Under Development

Secure local organizational intelligence platform for private document retrieval, grounded assistance, meeting workflows, tenancy, ChromaDB retrieval, and Ollama-based local AI.

Project page

AI Interview Platform

Status: Completed

Local-AI powered interview preparation and assessment platform using Django, Django REST Framework, FastAPI, Ollama, resume analysis, structured assessment, and gamified practice.

Project page

Core Toolkit

Backend & Systems

Python | Django | Django REST Framework | FastAPI | PostgreSQL | Redis | Celery

AI Engineering

Ollama | Local LLMs | RAG | ChromaDB | Agentic Workflows

Security Engineering

Application Security | API Security | Secure Code Review | Vulnerability Research | Security Automation | Log Analysis

Engineering Infrastructure

Docker | Linux | Git | GitHub Actions | Nginx

Professional Experience

Python Developer / Cybersecurity Specialist / Project Coordinator - StepSharp Digital

July 2025 - Present

  • Build secure backend applications, APIs, internal tooling, and automation workflows.
  • Conduct vulnerability assessments and security reviews.
  • Integrate AI-assisted features into application workflows.

Lead Python Django Developer - DevVerx

Jan 2025 - Mar 2025

  • Led Django application development and REST API implementation.
  • Improved backend architecture and database performance for HRMS and automation workflows.

Software Engineer - Code Circle (Pvt) Ltd

Oct 2023 - Jan 2025

  • Built Django and JavaScript applications, including AI-powered product features.
  • Improved API performance and collaborated across product and engineering workflows.

Education & Training

  • Python Django Development - Azad Chaiwala Institute
  • Master in ChatGPT - UNIATHENA
  • Prompt Engineering - Udemy

GitHub Activity

Zain Nadeem GitHub contribution summary

Connect

Pinned Loading

  1. Z-SHIELD-Advanced-Shell-Based-Cybersecurity-Toolkit Z-SHIELD-Advanced-Shell-Based-Cybersecurity-Toolkit Public

    A professional shell-based cybersecurity toolkit for recon, exploitation, post-exploitation, malware analysis, and network monitoring.

    Shell

  2. zainnadeem786.github.io zainnadeem786.github.io Public

    HTML

  3. SecOps-Analyst SecOps-Analyst Public

    TypeScript