Autonomous, self-hosted security testing for authorized bug bounty and pentesting.
BugTraceAI combines AI-guided investigation with deterministic security tools. The AI prioritizes hypotheses; tools execute checks, validate evidence, and produce reports that researchers can inspect and reuse.
![]() |
![]() |
| Discover and prioritize API surface | Follow autonomous work in real time |
| CVEs disclosed | Presented on stage |
|---|---|
| Wallos - CVE-2026-27479 - CVSS 7.7 | RootedCON 2026, Madrid |
| ZoneMinder - CVE-2026-27470 - CVSS 8.8 | HKOSCon 2026, Hong Kong |
| Piwigo - CVE-2026-27834 - CVSS 7.2 | DEF CON 34, Las Vegas |
| Project | What it gives you | Start here |
|---|---|---|
| BugTraceAI | The complete self-hosted platform and product overview. | Explore the platform |
| BugTraceAI-CLI | Autonomous scanner with a six-phase pipeline, specialist agents, validation, and reporting. | Run the CLI |
| BugTraceAI-WEB | Web workspace for analysis, real-time scan control, reporting, and AI-assisted research. | Open WEB |
| BugTraceAI-Launcher | Guided Docker deployment for the full platform, CLI, or WEB. | Deploy BugTraceAI |
| BugStore | Deliberately vulnerable practice target for safe local training and reproducible demos. | Practice on BugStore |
- Watch the DEF CON 34 demo to see the workflow end to end.
- Explore a real report generated against the BugStore practice target.
- Deploy with the Launcher or run a component independently.
- Join the Discord community for demos, feedback, and project discussion.
BugTraceAI is for educational and authorized security testing only. Always obtain explicit permission, respect target scope, and verify findings manually.


