Fredrik Dietrichson

Penetration Tester & Security Researcher

Norway

↓ Download CV

Summary

Penetration tester and security researcher at Semaphore Consulting Partners, with prior experience as a Red Team operator at PwC Norway. I perform web application, API, network, Active Directory, OT/ICS and IoT security assessments for clients across finance, energy, public sector, and transport.

Outside of client work I focus on independent security research and bug bounty programs, which has led to several published CVEs and advisories in open-source software.

Security research & CVEs

SSRF via HTTP Redirect Bypass — Papra

CVE-2026-48051 · GHSA-5g86-85rp-f9hx · May 2026

Found and reported a Server-Side Request Forgery vulnerability in Papra's webhook delivery system. The SSRF protection validated registered webhook URLs but ignored redirect destinations, allowing an authenticated user to make the server reach internal addresses.

Advisory →

Authorization Bypass: Payment Method Restriction — Sylius

CVE-2026-53638 · GHSA-6955-hrm5-c4qp · June 2026

Found and reported an authorization bypass in the Sylius shop account API. Authenticated customers could assign payment methods restricted by channel configuration, bypassing a check that was correctly enforced on the equivalent checkout endpoint.

Advisory →

BFLA in UpdateNamespaceMember — ShellHub

CVE-2026-58267 · GHSA-ww26-9cqf-x69q · July 2026

Found and reported a Broken Function Level Authorization vulnerability in ShellHub's namespace member management API. A namespace administrator could permanently demote the namespace owner to observer status, since the authorization check validated the assigned role but never whether the caller outranked the owner's existing role, and there was no way back through the API.

Advisory →

Authorization Bypass in GroupViewSet — Weblate

CVE-2026-55228 · GHSA-2q2q-jr9g-v9rf · July 2026

Found and reported an authorization flaw in Weblate's GroupViewSet API that let an authenticated project manager misconfigure project- and workspace-scoped teams to gain unauthorized read access to private projects (CVSS 8.1).

Advisory →

Unauthorized Access to Personal Data — Frappe ERPNext

GHSA-39rf-vr57-g568 · August 2026

Found and reported missing authorization validation in ERPNext that allowed authenticated users to access personal data beyond their assigned role permissions (CVSS 6.5).

Advisory →

Stored XSS via Filename in Roxy Fileman — nopCommerce

CVE-2026-50808 · September 2026

Found and reported a stored Cross-Site Scripting vulnerability in nopCommerce's admin file upload functionality (Roxy Fileman). Filenames were not sanitized or encoded before storage or display, so a malicious filename could execute script in an administrator's session, enabling session hijacking and privilege escalation. Unpatched at time of writing.

Write-up →

Stored XSS in Public Share Viewer — Joplin

CVE-2026-46650 · GHSA-x9vj-jrqf-9wcm · September 2026

Found and reported a stored XSS vulnerability in Joplin Server's public note-sharing feature. An unanchored regex used to validate internal resource URLs could be bypassed with a crafted javascript: URL, allowing script execution in the server's origin via a publicly shared note with no authentication required.

Advisory →

WeKan Security Hall of Fame

Responsible disclosure recognition

Listed in the WeKan Hall of Fame for responsibly reporting a Broken Function Level Authorization vulnerability (CVSS 8.1) affecting 48 REST endpoints in the open-source kanban platform.

Recognition →

Core skills

  • Penetration testing
  • Web application security
  • API security testing
  • Active Directory & Windows security
  • Vulnerability research & analysis
  • OSINT
  • IoT & hardware hacking
  • Physical security & lockpicking
  • OT/ICS security testing
  • Assumed-breach & internal network testing
  • Purple team exercises
  • Phishing & email security testing
  • Cloud (Azure / Entra ID) security
  • Security awareness training & talks

Experience

Penetration Tester & Security Expert — Semaphore Consulting Partners

Ethical hacking and security assessments for clients across finance, energy, public sector and transport as Penetration Tester, Test Lead and Project Lead.

  • Web & API penetration testing across varied stacks (React, C#, Kotlin/Spring Boot, Blazor), including e-commerce and SaaS platforms
  • Internal network and Active Directory / Entra ID assessments, including assumed-breach scenarios
  • OT/ICS assessments of industrial and factory networks
  • Security talks and training — secure coding, how penetration testing works, and lockpicking workshops

Red Team Operator — PwC Norway

Part of the PwC Red Team (Cyber Threat Operations) as an ethical hacker.

  • Penetration tests, red team engagements, and technical security consultancy for national and international clients
  • External and internal network testing, Active Directory, and OT/ICS assessments
  • Development of internal tooling
  • Purple-team detection exercises across the energy and public sectors

Intern — Cyber Security and Privacy — PwC Norway

Introduction to red team operations, IAM / PAM solutions and GRC.

Community & speaking

  • BSides Oslo — Lockpicking Village Co-organizer & instructor · 2024 & 2025 — taught physical-security and lockpicking fundamentals to attendees.

Earlier experience

  • Student Assistant — University of South-Eastern Norway 2021–2022 · Teaching assistant, introductory PHP programming
  • Trainee — Innovation Norway 2013–2014 · Royal Norwegian Embassy, Tokyo

Earlier roles in marketing, consultancy, and research (2007–2022) — full history in the CV.

Certifications

  • Practical IoT Pentest Associate — TCM Security Hands-on IoT/hardware security: ROM flashers, logic analyzers, UART/SPI protocols, firmware extraction and reverse engineering, vulnerability identification and professional reporting.
  • Microsoft Certified: Azure Fundamentals (AZ-900) — Microsoft Foundational knowledge of cloud concepts, Azure management, services and tools.

Relevant courses

  • OffSec WEB-300 — Advanced Web Attacks and Exploitation (2024) Prototype pollution, SSRF, .NET deserialization, RCE, blind SQL injection, source code review, persistent XSS, session hijacking.
  • TCM Security Linux & Windows Privilege Escalation, OSINT, and Practical Ethical Hacking (2023)

Full course list in the CV.

Education

  • BSc, Computer and Information Sciences — University of South-Eastern Norway 2020–2023
  • BA, Japanese Language and Literature — University of Oslo 2007–2010
  • Web development course — NTNU 2018
  • International marketing courses — BI Norwegian Business School 2010–2012

Languages

  • Norwegian Native
  • English Professional working
  • Japanese Working proficiency

Interests

Physical security and lockpicking, hardware tinkering and soldering projects, 3D printing, and hands-on testing of new offensive tooling (e.g. Flipper Zero). I also enjoy reading books on penetration testing and hardware hacking, and following the latest in AI/LLM security research.

Contact

contact@fredrikd.com

References available on request.