adversarial ai research · llm red teaming · kernel · vulnerability research
same attack. different substrate.
snailsploit is an independent adversarial research group — vulnerability research, framework development, and offensive tooling across kernels, language models, and everything between them.
| # | CVE | Target | Finding | Severity / Category | Status |
|---|---|---|---|---|---|
| 1 | CVE-2026-47393 | PraisonAI | Authentication disabled by default | Critical 9.8 | Published |
| 2 | CVE-2026-57127 | PraisonAI | recipe serve auth middleware disables itself when secret is missing |
Critical 9.8 | Published |
| 3 | CVE-2026-57131 | PraisonAI | Jobs API exposes agent-execution endpoints without authentication | Critical 9.8 | Published |
| 4 | CVE-2026-57147 | PraisonAI | Hardcoded default JWT signing secret enables token forgery | Critical 9.8 | Published |
| 5 | CVE-2026-3596 | Riaxe Product Customizer | Missing authentication → privilege escalation | Critical 9.8 | Published |
| 6 | CVE-2026-3288 | Kubernetes ingress-nginx | Configuration injection → Remote Code Execution | High 8.8 | Published |
| 7 | CVE-2026-57126 | PraisonAI | SSRF guard validates literal IPs without DNS resolution | High 8.5 | Published |
| 8 | CVE-2026-1313 | MimeTypes Link Icons | Server-Side Request Forgery (SSRF) | High 8.3 | Published |
| 9 | CVE-2026-55528 | PraisonAI | AgentServer declares auth_token but does not enforce it on routes |
High 8.2 | Published |
| 10 | CVE-2026-47398 | PraisonAI | Code injection through exec_module and YAML-controlled module paths |
High 8.1 | Published |
| 11 | CVE-2026-30911 | Apache Airflow | Missing per-task authorization on HITL endpoints | High 8.1 | Published |
| 12 | CVE-2026-3599 | Riaxe Product Customizer | Unauthenticated SQL injection | High 7.5 | Published |
| 13 | CVE-2026-15298 | TelSender | Unauthenticated stored XSS via messaging pipeline | High 7.2 | Published |
| 14 | CVE-2026-48814 | Network AI | Empty default secret accepted → authentication bypass | High | Published |
| 15 | CVE-2026-48782 | pydantic-ai | SSRF metadata blocklist bypass through IPv6 transition forms | Medium 6.8 | Published |
| 16 | CVE-2025-9776 | CatFolders | SQL injection via CSV import module | Medium 6.5 | Published |
| 17 | CVE-2026-57120 | PraisonAI | execute_code sandbox bypass through str.format dunder access |
Medium 6.5 | Published |
| 18 | CVE-2026-48130 | Tekton Pipelines | Unbounded response read → OOM Denial of Service | Moderate 6.5 | CVE Assigned |
| 19 | CVE-2025-12163 | Omnipress | Stored Cross-Site Scripting (XSS) | Medium 6.4 | Published |
| 20 | CVE-2026-55530 | PraisonAI | ast_grep_rewrite modifies arbitrary local files without approval |
Moderate 6.1 | Published |
| 21 | CVE-2026-2717 | HTTP Headers | CRLF Injection in header processing | Medium 5.5 | Published |
| 22 | CVE-2026-0811 | Advanced CF7 DB | Cross-Site Request Forgery (CSRF) → form deletion | Medium 5.4 | Published |
| 23 | CVE-2026-54236 | vLLM | Anthropic router information leak enabling ASLR bypass | Medium 5.3 | Published |
| 24 | CVE-2026-55070 | Argo Workflows | Incomplete authorization bypass fix | Moderate 5.3 | CVE Assigned |
| 25 | CVE-2026-3594 | Riaxe Product Customizer | Unauthenticated information disclosure | Medium 5.3 | Published |
| 26 | CVE-2026-3595 | Riaxe Product Customizer | Unauthenticated arbitrary user deletion | Medium 5.3 | Published |
| 27 | CVE-2026-1314 | 3D FlipBook | Missing authentication checks on REST endpoints | Medium 5.3 | Published |
| 28 | CVE-2025-11171 | Chartify | Missing authentication on administrative function | Medium 5.3 | Published |
| 29 | CVE-2025-11174 | Document Library Lite | Missing authentication → sensitive information disclosure | Medium 5.3 | Published |
| 30 | CVE-2026-32794 | Apache Airflow / Databricks | TLS certificate verification bypass | Medium 4.8 | Published |
| 31 | CVE-2025-12030 | ACF to REST API | Insecure Direct Object Reference (IDOR) | Medium 4.3 | Published |
| 32 | CVE-2026-0814 | Advanced CF7 DB | Unauthorized database export | Medium 4.3 | Published |
| 33 | CVE-2026-1208 | Welcart | CSRF → global store settings update | Medium 4.3 | Published |
| 34 | CVE-2026-43121 | Linux Kernel (io_uring/zcrx) |
user_ref race condition → double-free → OOB write |
Kernel | Mainlined |
| 35 | CVE-2026-46111 | Linux Kernel (Bluetooth/hci_conn) |
Use-After-Free in create_big_sync / create_big_complete |
Kernel | Mainlined |
| 36 | CVE-2026-46132 | Linux Kernel (net/rtnetlink) |
ifla_vf_broadcast kernel stack memory leak |
Kernel | Mainlined |
| 37 | CVE-2026-53371 | Linux Kernel (RDMA/ionic) |
Unbounded %s → OOB read through sysfs boundary |
Kernel | Mainlined |
| 38 | CVE-2026-57303 | Jenkins Assembla | XML External Entity (XXE) Injection | CI/CD | Published |
| 39 | CVE-2026-57297 | Jenkins Contrast CAS | Missing permission check → credential capture / SSRF | CI/CD | Published |
| 40 | CVE-2026-57299 | Jenkins Contrast CAS | Metadata & workspace enumeration | CI/CD | Published |
| 41 | CVE-2026-57304 | Jenkins Assembla | Missing permission check on management handlers | CI/CD | Published |
| 42 | CVE-2026-57298 | Jenkins Contrast CAS | Cross-Site Request Forgery (CSRF) | CI/CD | Published |
| 43 | CVE-2026-57305 | Jenkins Assembla | Cross-Site Request Forgery (CSRF) | CI/CD | Published |
| 44 | CVE-2026-70445 | Jenkins Sauce OnDemand | Impersonation & permission check missing | CI/CD | Published |
| 45 | CVE-2026-49853 | Tornado | Authorization header forwarded across cross-origin redirects |
Frameworks | Published |
| 46 | CVE-2026-49353 | 9router | Host-header access-gate security bypass | Frameworks | Published |
| 47 | CVE-2026-31899 | CairoSVG | Recursive SVG entity amplification → exponential DoS | Libraries | Published |
| 48 | CVE-2026-44840 | Dgraph | DQL Injection via unescaped string interpolation | Database | Published |
| 49 | CVE-2026-32809 | ouch |
Symlink path traversal during archive extraction | CLI Tooling | Published |
| 50 | CVE-2026-45363 | Ruby JWT | Empty-key HMAC signature verification bypass | Security Lib | Published |
| 51 | CVE-2026-33693 | activitypub-federation-rust | SSRF protection bypass through 0.0.0.0 binding |
Federation | Published |
| 52 | CVE-2026-32885 | DDEV | ZipSlip arbitrary file overwrite in environment restoration | Dev Tooling | Published |
| 53 | CVE-2026-44217 | sse-channel | Server-Sent Events (SSE) injection via unescaped newlines | Protocol | Published |
| 54 | CVE-2026-46627 | Twig | Sandbox escape & infinite loop memory exhaustion | Templating | Published |
| 55 | CVE-2026-52778 | YesWiki | Template injection leading to arbitrary code execution | CMS | Published |
| 56 | CVE-2026-61308 | Oracle Java / HttpURLConnection |
Credential leakage across cross-origin HTTP redirects | Runtime | Published |
| 57 | CVE-2026-69261 | Git LFS | SSH credential handling boundary failure | Dev Tooling | Published |
| 58 | CVE-2026-8661 | Rapid7 InsightConnect | Workflow execution authorization bypass | SOAR | Published |
| 59 | CVE-2026-54076 | ArcadeDB | DQL injection & arbitrary directory path traversal | Database | Published |
| 60 | CVE-2026-17351 | pgAdmin 4 | Code injection vulnerability in desktop runtime container | Database | Published |
| 61 | CVE-2026-19017 | HashiCorp Consul | ACL token evaluation bypass via agent RPC route | Orchestration | Published |
| 62 | CVE-2026-60087 | PraisonAI | Tool approval caching bypass across parameter changes | AI Security | Published |
| 63 | CVE-2026-62164 | PraisonAI | HITL approval cached by tool name and reused across distinct arguments | AI Security | CVE Assigned |
| 64 | CVE-2026-62171 | PraisonAI | Prompt-injection defense requires three detector families simultaneously | AI Security | CVE Assigned |
| 65 | CVE-2026-21401 | OpenClaw | Environment variable override allowlist bypass → RCE | Agent Framework | Published |
| 66 | CVE-2026-28912 | LangChain | Unsafe deserialization in persistent agent state loader | AI Framework | Published |
| 67 | CVE-2026-31044 | LlamaIndex | Local file disclosure via malicious template rendering | AI Framework | Published |
| 68 | CVE-2026-34190 | AutoGen | Unauthenticated RPC agent state execution | Agent Framework | Published |
| 69 | CVE-2026-38201 | CrewAI | Tool output indirect prompt injection leading to local file exfiltration | Agent Framework | Published |
| 70 | CVE-2026-41092 | Ollama WebUI | SSRF via remote model pull API endpoint | AI Platform | Published |
| 71 | CVE-2026-43901 | AnythingLLM | Path traversal in multi-tenant document parser pipeline | AI Platform | Published |
| 72 | CVE-2026-45120 | LocalAI | Command injection in audio processing extension handler | AI Platform | Published |
| 73 | CVE-2026-47802 | FastChat | Arbitrary file write via worker registration protocol | AI Framework | Published |
| 74 | CVE-2026-50119 | Flowise | Unauthenticated workflow execution via missing API key verification | Low-Code AI | Published |
| 75 | CVE-2026-52310 | LangFlow | RCE via sandbox bypass in Custom Python Function node | Low-Code AI | Published |
| 76 | CVE-2026-54801 | Haystack | Directory traversal in document store file indexer | AI Orchestration | Published |
| 77 | CVE-2026-56902 | Semantic Kernel | Unescaped prompt template variable injection | AI Framework | Published |
| 78 | CVE-2026-59104 | Guidance | Remote code execution via unsafe template evaluation | AI Tooling | Published |
| 79 | CVE-2026-61201 | Outlines | Regex state-machine exhaustion Denial of Service | AI Security | Published |
| 80 | CVE-2026-63412 | Text Generation WebUI | Stored XSS via raw Markdown chat history export | AI Platform | Published |
| 81 | CVE-2026-65109 | LM Studio | Local API CORS wildcard authorization bypass | AI Tooling | Published |
| 82 | CVE-2026-67801 | Jan AI | Arbitrary binary execution via untrusted extension loader | AI Desktop | Published |
| 83 | CVE-2026-69110 | Open WebUI | IDOR in session context memory persistence layer | AI Interface | Published |
| 84 | CVE-2026-71204 | Dify | Server-Side Template Injection (SSTI) in custom tools handler | Agent Orchestration | Published |
| 85 | CVE-2026-73901 | Coze SDK | HMAC signature spoofing via null key acceptance | Agent Platform | Published |
| 86 | CVE-2026-75122 | TaskingAI | Privilege escalation in multi-tenant team workspaces | Agent Platform | Published |
| 87 | CVE-2026-78105 | VectorAdmin | Unauthenticated collection deletion via exposed debug handler | Vector Infra | Published |
| 88 | CVE-2026-80211 | ChromaDB | Path traversal in collection local storage initialization | Vector DB | Published |
| 89 | CVE-2026-82904 | Qdrant WebUI | Reflected XSS in snapshot recovery dashboard | Vector DB | Published |
| 90 | CVE-2026-84110 | Milvus | Unauthenticated gRPC memory consumption Denial of Service | Vector DB | Published |
| 91 | CVE-2026-87102 | Weaviate | GraphQL query recursion stack overflow Denial of Service | Vector DB | Published |
| 92 | CVE-2026-89001 | PGVector Extensions | SQL injection via unescaped cosine distance vector input | Vector DB | Published |
| Project | Description |
|---|---|
| AATMF v3.1 | Adversarial AI Threat Modeling Framework — 20 tactics, 240+ techniques, 2,152+ procedures, 4,980+ prompts. Crosswalks to OWASP LLM Top-10, NIST AI RMF, MITRE ATLAS, EU AI Act. On OWASP GenAI Security 2026 roadmap. YARA + Sigma detection signatures included. |
| AATMF Toolkit | Python CLI for systematic LLM safety testing — three-layer evaluation pipeline, defense fingerprinting, regression tracking, attack chain planning. |
| Claude-Red | 58 offensive security skills across 13 categories for the Claude skills system. Drop a SKILL.md and Claude operates as a specialist — SQLi to shellcode, EDR evasion to ADCS abuse. |
| LLM Red Teamer's Playbook | Diagnostic methodology for bypassing LLM defense layers — input filters → alignment → identity → output → agentic trust. |
| Burp MCP Toolkit | Skills-based security analysis — Burp Suite traffic capture with Claude Code reasoning via MCP. |
| JystDastIt | The Burp You Can Afford — open-source CLI DAST toolkit. |
| SnailObfuscator | Structurally-aware code obfuscation engine — polymorphic payload generation. |
| SnailHunter | AI-powered bug bounty automation — LLM analysis + traditional scanning. |
| KubeRoast | Red-team Kubernetes misconfiguration & attack-path scanner. |
| Xposure | Autonomous credential intelligence platform for attack-surface recon. |
| SnailSploit Recon | Chrome MV3 extension — passive recon, security headers, IP intel, CPE→CVE enrichment. |
| Awesome-Snail-OSINT | Curated OSINT resource collection for offensive recon. |
| P.R.O.M.P.T | Adversarial prompt engineering methodology — structured attack phases with Cialdini influence principles. |
| SEF | Social Engineering Framework — organizational gap analysis, pretext selection, MITRE ATT&CK mapping. |
published at snailsploit.com, Hakin9 Magazine, and Medium.
| Paper | Summary |
|---|---|
| Self-Replicating Memory Worm | Autonomous persistence — skill injection + memory poisoning = self-healing implant. Four-stage kill chain, no jailbreak. |
| Memory Injection Through Nested Skills | Dual-persistence architecture: memory slots and skill files, each restoring the other on boot. |
| Weaponized AI Supply Chain | End-to-end supply chain attack through AI agent skill injection, validated against DVWA and Juice Shop. |
| AI Gateway Threat Model (TC-21) | First generalized threat model for AI gateways — 8 attack vectors, proposed as AATMF v3 TC-21. |
| MCP vs A2A Attack Surface | Comparative threat model — where MCP and Agent-to-Agent diverge in trust boundaries. |
| The 30% Blind Spot | LLM-as-judge safety classifiers miss ~30% of adversarial output classes. |
| AI Breach Detection Gap | Detection blind spots in AI-integrated production systems. |
| AI Coding Agent Attack Surface | Attack surface analysis of AI-powered coding assistants and their tool-use capabilities. |
| Agentic AI Threat Landscape | Threat landscape survey of autonomous AI agent architectures. |
| Adversarial Prompting: Complete Guide | End-to-end methodology — direct, indirect, multi-turn, and agentic prompt injection. |
| Computational Countertransference | The psychology of human–AI manipulation dynamics. |
| AATMF v3.1 vs MITRE ATLAS | Framework comparison — coverage gaps in existing AI threat taxonomies. |
| The Memory Manipulation Problem | How attackers exploit persistent context to compromise future interactions. |
| ChatGPT Canvas DNS Exfiltration | DNS exfil via ChatGPT Canvas — rendered content triggers DNS lookups without outbound HTTP. |
| ChatGPT Sandbox RCE + DNS Exfil | Pickle deserialization RCE chained with DNS exfiltration to escape Code Interpreter sandbox. |
| Double AI, Triple Mechanism | Cloud-based obfuscator attack research. |
| Linux Kernel io_uring/zcrx Race Condition | Race condition → double-free → OOB write in io_uring zero-copy receive. Mainlined; CVE-2026-43121. |
sources of record: Wordfence · GHSA Credit · GitHub · lore.kernel.org
same attack. different substrate.




