Bring-your-own-agent security research

Bring your own agent.
Prove every finding.

Point your own Claude Code or Codex at a repo. It scores each lead on the evidence behind it and keeps the advisory locked until you've run the proof-of-concept and watched it cross the boundary. None of it leaves your machine.

macOS · Windows · Linux·your code never leaves your machine
finding · live
PoC ready
71HIGH

FTP ignores --upload-only

8.5HIGH

goshs v2.1.0 · incorrect authorization

sourceftpserver.go:101 AuthUser
sinkRETR / LIST / DELE served
no upload-only branch → full filesystem

Disclosure locked

validate the PoC to unlock

Your engine, your machine

Run it with the agent you already trust.

VulntraceAI doesn't ship a model. It drives your own Claude Code or Codex over the repo, right on your machine, tracing each candidate from source to sink phase by phase. Nothing is uploaded and nothing runs in a black box you can't inspect.

detected

Claude Code

Anthropic · Opus · Sonnet

$ claude --version

detected

Codex

OpenAI · GPT-5 class

$ codex --version

Any agent on your PATH works. Your code, credentials, and PoC runs never leave the device — the cloud only ever sees a finding's shape: class, CVSS, confidence, and file:line.

The gate

No proof, no advisory.

No advisory, no CVSS, no disclosure text exists until a human runs the proof-of-concept and confirms it. The lock lives in the code path, not in a guideline — which is the part most tools leave to your good intentions.

Discovered
Triaged
PoC ready
Validating
Validated
Disclosure ready

unlock_reporting() needs your explicit confirmation plus ≥2 independent evidence signals. Model reasoning alone can never open it.

Track record

The highest-severity CVEs, credited.

The top findings by CVSS across the community — every row a publicly credited advisory, surfaced by an agent and proven with a PoC before disclosure.

spotlight
9.8CRITICAL
94CONFIRMED
source controllable
sanitizer absent
boundary crossed
PoC validated

Empty-username SFTP auth bypass

goshs · CVE-2026-40884

sourcessh.ServerConn{User:""}
sinkPasswordCallback() ⇒ ok
blank username skips the credential check
cvefindingcvss
  • CVE-2026-40884goshsEmpty-username SFTP password auth bypass9.8CRITICAL
  • CVE-2026-42596GotenbergUnauthenticated SSRF via default deny-list bypass9.4CRITICAL
  • CVE-2026-40189goshsFile-based ACL authorization bypass9.3CRITICAL
  • CVE-2026-40289PraisonAIUnauthenticated WebSocket session hijack9.1CRITICAL
  • CVE-2026-40876goshsSFTP root escape via prefix-based path validation8.7HIGH
  • CVE-2026-42221nginx-uiFirst-run installer claims initial admin8.1HIGH
  • CVE-2026-40885goshsPublic collaborator feed leaks ACL credentials7.5HIGH
  • CVE-2026-39308PraisonAIRecipe registry publish path traversal7.3HIGH
  • CVE-2026-39306PraisonAIRecipe registry pull path traversal7.3HIGH
  • CVE-2026-40883goshsCSRF in state-changing GET routes6.5MEDIUM
0credited CVEs
0rated critical
0researcher
Inside a run

How a finding earns its disclosure.

01

Scan a repo

Point the local Companion at owner/repo. Eight phases run on your machine — your code never leaves it.

02

Score & triage

Each candidate gets a multi-signal confidence score. Lone pattern hits are capped low by design.

03

Generate a PoC

A safe, local-only verifier with a negative control. We tell you to stop and run it yourself.

04

Validate

Run it, confirm the evidence, type the phrase. The lock springs open — and only then.

05

Disclose

Advisory, CVSS v4, and a maintainer-acceptance estimate. You file it privately. We never auto-submit.

Recon → Architecture → Intent → Advisories → Attack surface → Deep analysis → Validation → Report

Your next CVE is one run away.

Run it in the browser, or pair the Companion and keep every byte of your code local.