[SECURITY RESEARCH]

AI Research in
Application Security

AI Research in
Application Security

AI Research in
Application Security

Vulnerabilities we found, exploits we built, patterns we keep seeing

CVE-2026-31988: One Malformed Zip File Crashes Your Node.js Server: DoS in npm's Most Downloaded Zip Library (29M+ Weekly Downloads)

Mar 11, 2026

CVE-2026-31988: One Malformed Zip File Crashes Your Node.js Server: DoS in npm's Most Downloaded Zip Library (29M+ Weekly Downloads)

Mar 11, 2026

[DISCLOSURES]

All Research

Every vulnerability we've reported, with the reproduction steps and the patch that fixed it.

Mar 9, 2026

CVE-2026-28292: simple-git Remote Code Execution, One Uppercase Letter Bypasses Two CVE Patches (CVSS 9.8)

Mar 3, 2026

CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)

Mar 9, 2026

CVE-2026-28292: simple-git Remote Code Execution, One Uppercase Letter Bypasses Two CVE Patches (CVSS 9.8)

CVE-2026-28292

CVSS 9.8 CRITICAL

NPM

Mar 3, 2026

CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)

CVE-2026-29000

CVSS 10.0 CRITICAL

JAVA

[GET STARTED]

Let AI Fix Your Code,
You Build the Future

START PENTEST

NO CC REQUIRED