███████╗██╗  ██╗██╗   ██╗██████╗ ██╗  ██╗
 ██╔════╝██║  ██║██║   ██║██╔══██╗██║  ██║
 ███████╗███████║██║   ██║██████╔╝███████║
 ╚════██║██╔══██║██║   ██║██╔══██╗██╔══██║
 ███████║██║  ██║╚██████╔╝██████╔╝██║  ██║
 ╚══════╝╚═╝  ╚═╝ ╚═════╝ ╚═════╝ ╚═╝  ╚═╝
shubh@portfolio:~$whoami

Shubh Mehta

I'm a

# building reliable backend systems and the tooling around them.
# currently obsessed with clean monorepos and typed-everything.

Shubh Mehta
shubh@portfolio:~$cat about.md
about.md

Full-stack web developer, cyber-security researcher, and bug-bounty hunter. I write a lot of Go, deploy a lot of containers, and spend more time than I'd like to admit reading proto files and intercepted HTTP requests.

# education
B.Tech in Computer Science & Engineering at IIIT-DM Jabalpur (Dec 2021 — Jun 2025).

Outside of work — competitive programming (Codeforces specialist, LeetCode 200+), breaking things to learn how they're built, and the occasional half-broken side project.

shubh@portfolio:~$ps aux --sort=-cpu
top — skills
PIDUSER%CPUNAMELEVEL
101shubh94.2goexpert
102shubh90.1react/nextadvanced
103shubh88.7node/expressadvanced
104shubh86.1kubernetesadvanced
105shubh82.4dockeradvanced
106shubh80.0typescriptadvanced
107shubh74.8mongodbproficient
108shubh72.3burpsuite/pentestproficient
109shubh65.8c++proficient
shubh@portfolio:~$ls -la projects/
shubh@portfolio:~$tail -n 20 experience.log
experience.log
# May 2026 — present
GSoC Mentor@Google Summer of Code
Mentoring contributors on open-source projects — code review, design feedback, and helping new folks ship their first real PRs.
# Jul 2025 — present
Software Engineer@EvenHealthcare
Maintaining Go services and production servers, leading Bazel monorepo migration, and driving infrastructure cost reduction.
# Feb 2025 — Mar 2025
Software Engineering Intern@Mercari (Japan)
Worked on Mercari's flagship C2C product — built modular UI components, instrumented Laplace-based logging for observability, wrote unit test suites to cut regression risk, and collaborated with the Search team to revamp UI responsiveness and accessibility.
# May 2024 — Sep 2024
GSoC Contributor@C2SI · Google Summer of Code
Built GDB-UI under c2siorg — a browser-based interface for GDB debugger sessions, removing the need for the bare CLI.
# May 2024 — Aug 2024
SDE Intern@Tranzact
Backend developer intern — building and maintaining production services, APIs, and database workflows.
shubh@portfolio:~$cat bugs.log
bugs.log — security advisories

# responsibly-disclosed findings, ordered by date.

DATESEVERITYTARGETFINDING
2023CRITICALBoatzonBusiness-logic flaw — 100% discount via price manipulation
# Users could manipulate the price field in checkout requests to apply a 100% discount. Reported with reproduction steps for swift resolution.
2023HIGHSwiggyOTP bypass on partner-with-us subdomain
# Server returned the auth state in the response body without proper server-side enforcement — flipping a boolean granted login access.
2023MEDIUMTriple-A4× broken access control — privilege escalation to admin
# Found four endpoints where lower-privileged users could invoke admin-only functionality. Bundled into one disclosure with PoC for each.
2023MEDIUMIndeedOpen-redirect vulnerability
# Redirect parameter accepted external URLs without validation. Reported responsibly with allow-list mitigation suggestion.
shubh@portfolio:~$./contact.sh