Skip to content

Latest commit

 

History

17 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

snailsploit — same attack. different substrate.

adversarial ai research · llm red teaming · kernel · vulnerability research

Website The Jailbreak Chef LinkedIn Medium


same attack. different substrate.

snailsploit is an independent adversarial research group — vulnerability research, framework development, and offensive tooling across kernels, language models, and everything between them.


Complete CVE Corpus (Kai Aizen)

# CVE Target Finding Severity / Category Status
1 CVE-2026-47393 PraisonAI Authentication disabled by default Critical 9.8 Published
2 CVE-2026-57127 PraisonAI recipe serve auth middleware disables itself when secret is missing Critical 9.8 Published
3 CVE-2026-57131 PraisonAI Jobs API exposes agent-execution endpoints without authentication Critical 9.8 Published
4 CVE-2026-57147 PraisonAI Hardcoded default JWT signing secret enables token forgery Critical 9.8 Published
5 CVE-2026-3596 Riaxe Product Customizer Missing authentication → privilege escalation Critical 9.8 Published
6 CVE-2026-3288 Kubernetes ingress-nginx Configuration injection → Remote Code Execution High 8.8 Published
7 CVE-2026-57126 PraisonAI SSRF guard validates literal IPs without DNS resolution High 8.5 Published
8 CVE-2026-1313 MimeTypes Link Icons Server-Side Request Forgery (SSRF) High 8.3 Published
9 CVE-2026-55528 PraisonAI AgentServer declares auth_token but does not enforce it on routes High 8.2 Published
10 CVE-2026-47398 PraisonAI Code injection through exec_module and YAML-controlled module paths High 8.1 Published
11 CVE-2026-30911 Apache Airflow Missing per-task authorization on HITL endpoints High 8.1 Published
12 CVE-2026-3599 Riaxe Product Customizer Unauthenticated SQL injection High 7.5 Published
13 CVE-2026-15298 TelSender Unauthenticated stored XSS via messaging pipeline High 7.2 Published
14 CVE-2026-48814 Network AI Empty default secret accepted → authentication bypass High Published
15 CVE-2026-48782 pydantic-ai SSRF metadata blocklist bypass through IPv6 transition forms Medium 6.8 Published
16 CVE-2025-9776 CatFolders SQL injection via CSV import module Medium 6.5 Published
17 CVE-2026-57120 PraisonAI execute_code sandbox bypass through str.format dunder access Medium 6.5 Published
18 CVE-2026-48130 Tekton Pipelines Unbounded response read → OOM Denial of Service Moderate 6.5 CVE Assigned
19 CVE-2025-12163 Omnipress Stored Cross-Site Scripting (XSS) Medium 6.4 Published
20 CVE-2026-55530 PraisonAI ast_grep_rewrite modifies arbitrary local files without approval Moderate 6.1 Published
21 CVE-2026-2717 HTTP Headers CRLF Injection in header processing Medium 5.5 Published
22 CVE-2026-0811 Advanced CF7 DB Cross-Site Request Forgery (CSRF) → form deletion Medium 5.4 Published
23 CVE-2026-54236 vLLM Anthropic router information leak enabling ASLR bypass Medium 5.3 Published
24 CVE-2026-55070 Argo Workflows Incomplete authorization bypass fix Moderate 5.3 CVE Assigned
25 CVE-2026-3594 Riaxe Product Customizer Unauthenticated information disclosure Medium 5.3 Published
26 CVE-2026-3595 Riaxe Product Customizer Unauthenticated arbitrary user deletion Medium 5.3 Published
27 CVE-2026-1314 3D FlipBook Missing authentication checks on REST endpoints Medium 5.3 Published
28 CVE-2025-11171 Chartify Missing authentication on administrative function Medium 5.3 Published
29 CVE-2025-11174 Document Library Lite Missing authentication → sensitive information disclosure Medium 5.3 Published
30 CVE-2026-32794 Apache Airflow / Databricks TLS certificate verification bypass Medium 4.8 Published
31 CVE-2025-12030 ACF to REST API Insecure Direct Object Reference (IDOR) Medium 4.3 Published
32 CVE-2026-0814 Advanced CF7 DB Unauthorized database export Medium 4.3 Published
33 CVE-2026-1208 Welcart CSRF → global store settings update Medium 4.3 Published
34 CVE-2026-43121 Linux Kernel (io_uring/zcrx) user_ref race condition → double-free → OOB write Kernel Mainlined
35 CVE-2026-46111 Linux Kernel (Bluetooth/hci_conn) Use-After-Free in create_big_sync / create_big_complete Kernel Mainlined
36 CVE-2026-46132 Linux Kernel (net/rtnetlink) ifla_vf_broadcast kernel stack memory leak Kernel Mainlined
37 CVE-2026-53371 Linux Kernel (RDMA/ionic) Unbounded %s → OOB read through sysfs boundary Kernel Mainlined
38 CVE-2026-57303 Jenkins Assembla XML External Entity (XXE) Injection CI/CD Published
39 CVE-2026-57297 Jenkins Contrast CAS Missing permission check → credential capture / SSRF CI/CD Published
40 CVE-2026-57299 Jenkins Contrast CAS Metadata & workspace enumeration CI/CD Published
41 CVE-2026-57304 Jenkins Assembla Missing permission check on management handlers CI/CD Published
42 CVE-2026-57298 Jenkins Contrast CAS Cross-Site Request Forgery (CSRF) CI/CD Published
43 CVE-2026-57305 Jenkins Assembla Cross-Site Request Forgery (CSRF) CI/CD Published
44 CVE-2026-70445 Jenkins Sauce OnDemand Impersonation & permission check missing CI/CD Published
45 CVE-2026-49853 Tornado Authorization header forwarded across cross-origin redirects Frameworks Published
46 CVE-2026-49353 9router Host-header access-gate security bypass Frameworks Published
47 CVE-2026-31899 CairoSVG Recursive SVG entity amplification → exponential DoS Libraries Published
48 CVE-2026-44840 Dgraph DQL Injection via unescaped string interpolation Database Published
49 CVE-2026-32809 ouch Symlink path traversal during archive extraction CLI Tooling Published
50 CVE-2026-45363 Ruby JWT Empty-key HMAC signature verification bypass Security Lib Published
51 CVE-2026-33693 activitypub-federation-rust SSRF protection bypass through 0.0.0.0 binding Federation Published
52 CVE-2026-32885 DDEV ZipSlip arbitrary file overwrite in environment restoration Dev Tooling Published
53 CVE-2026-44217 sse-channel Server-Sent Events (SSE) injection via unescaped newlines Protocol Published
54 CVE-2026-46627 Twig Sandbox escape & infinite loop memory exhaustion Templating Published
55 CVE-2026-52778 YesWiki Template injection leading to arbitrary code execution CMS Published
56 CVE-2026-61308 Oracle Java / HttpURLConnection Credential leakage across cross-origin HTTP redirects Runtime Published
57 CVE-2026-69261 Git LFS SSH credential handling boundary failure Dev Tooling Published
58 CVE-2026-8661 Rapid7 InsightConnect Workflow execution authorization bypass SOAR Published
59 CVE-2026-54076 ArcadeDB DQL injection & arbitrary directory path traversal Database Published
60 CVE-2026-17351 pgAdmin 4 Code injection vulnerability in desktop runtime container Database Published
61 CVE-2026-19017 HashiCorp Consul ACL token evaluation bypass via agent RPC route Orchestration Published
62 CVE-2026-60087 PraisonAI Tool approval caching bypass across parameter changes AI Security Published
63 CVE-2026-62164 PraisonAI HITL approval cached by tool name and reused across distinct arguments AI Security CVE Assigned
64 CVE-2026-62171 PraisonAI Prompt-injection defense requires three detector families simultaneously AI Security CVE Assigned
65 CVE-2026-21401 OpenClaw Environment variable override allowlist bypass → RCE Agent Framework Published
66 CVE-2026-28912 LangChain Unsafe deserialization in persistent agent state loader AI Framework Published
67 CVE-2026-31044 LlamaIndex Local file disclosure via malicious template rendering AI Framework Published
68 CVE-2026-34190 AutoGen Unauthenticated RPC agent state execution Agent Framework Published
69 CVE-2026-38201 CrewAI Tool output indirect prompt injection leading to local file exfiltration Agent Framework Published
70 CVE-2026-41092 Ollama WebUI SSRF via remote model pull API endpoint AI Platform Published
71 CVE-2026-43901 AnythingLLM Path traversal in multi-tenant document parser pipeline AI Platform Published
72 CVE-2026-45120 LocalAI Command injection in audio processing extension handler AI Platform Published
73 CVE-2026-47802 FastChat Arbitrary file write via worker registration protocol AI Framework Published
74 CVE-2026-50119 Flowise Unauthenticated workflow execution via missing API key verification Low-Code AI Published
75 CVE-2026-52310 LangFlow RCE via sandbox bypass in Custom Python Function node Low-Code AI Published
76 CVE-2026-54801 Haystack Directory traversal in document store file indexer AI Orchestration Published
77 CVE-2026-56902 Semantic Kernel Unescaped prompt template variable injection AI Framework Published
78 CVE-2026-59104 Guidance Remote code execution via unsafe template evaluation AI Tooling Published
79 CVE-2026-61201 Outlines Regex state-machine exhaustion Denial of Service AI Security Published
80 CVE-2026-63412 Text Generation WebUI Stored XSS via raw Markdown chat history export AI Platform Published
81 CVE-2026-65109 LM Studio Local API CORS wildcard authorization bypass AI Tooling Published
82 CVE-2026-67801 Jan AI Arbitrary binary execution via untrusted extension loader AI Desktop Published
83 CVE-2026-69110 Open WebUI IDOR in session context memory persistence layer AI Interface Published
84 CVE-2026-71204 Dify Server-Side Template Injection (SSTI) in custom tools handler Agent Orchestration Published
85 CVE-2026-73901 Coze SDK HMAC signature spoofing via null key acceptance Agent Platform Published
86 CVE-2026-75122 TaskingAI Privilege escalation in multi-tenant team workspaces Agent Platform Published
87 CVE-2026-78105 VectorAdmin Unauthenticated collection deletion via exposed debug handler Vector Infra Published
88 CVE-2026-80211 ChromaDB Path traversal in collection local storage initialization Vector DB Published
89 CVE-2026-82904 Qdrant WebUI Reflected XSS in snapshot recovery dashboard Vector DB Published
90 CVE-2026-84110 Milvus Unauthenticated gRPC memory consumption Denial of Service Vector DB Published
91 CVE-2026-87102 Weaviate GraphQL query recursion stack overflow Denial of Service Vector DB Published
92 CVE-2026-89001 PGVector Extensions SQL injection via unescaped cosine distance vector input Vector DB Published

frameworks & tooling

Project Description
AATMF v3.1 Adversarial AI Threat Modeling Framework — 20 tactics, 240+ techniques, 2,152+ procedures, 4,980+ prompts. Crosswalks to OWASP LLM Top-10, NIST AI RMF, MITRE ATLAS, EU AI Act. On OWASP GenAI Security 2026 roadmap. YARA + Sigma detection signatures included.
AATMF Toolkit Python CLI for systematic LLM safety testing — three-layer evaluation pipeline, defense fingerprinting, regression tracking, attack chain planning.
Claude-Red 58 offensive security skills across 13 categories for the Claude skills system. Drop a SKILL.md and Claude operates as a specialist — SQLi to shellcode, EDR evasion to ADCS abuse.
LLM Red Teamer's Playbook Diagnostic methodology for bypassing LLM defense layers — input filters → alignment → identity → output → agentic trust.
Burp MCP Toolkit Skills-based security analysis — Burp Suite traffic capture with Claude Code reasoning via MCP.
JystDastIt The Burp You Can Afford — open-source CLI DAST toolkit.
SnailObfuscator Structurally-aware code obfuscation engine — polymorphic payload generation.
SnailHunter AI-powered bug bounty automation — LLM analysis + traditional scanning.
KubeRoast Red-team Kubernetes misconfiguration & attack-path scanner.
Xposure Autonomous credential intelligence platform for attack-surface recon.
SnailSploit Recon Chrome MV3 extension — passive recon, security headers, IP intel, CPE→CVE enrichment.
Awesome-Snail-OSINT Curated OSINT resource collection for offensive recon.
P.R.O.M.P.T Adversarial prompt engineering methodology — structured attack phases with Cialdini influence principles.
SEF Social Engineering Framework — organizational gap analysis, pretext selection, MITRE ATT&CK mapping.

research

published at snailsploit.com, Hakin9 Magazine, and Medium.

Paper Summary
Self-Replicating Memory Worm Autonomous persistence — skill injection + memory poisoning = self-healing implant. Four-stage kill chain, no jailbreak.
Memory Injection Through Nested Skills Dual-persistence architecture: memory slots and skill files, each restoring the other on boot.
Weaponized AI Supply Chain End-to-end supply chain attack through AI agent skill injection, validated against DVWA and Juice Shop.
AI Gateway Threat Model (TC-21) First generalized threat model for AI gateways — 8 attack vectors, proposed as AATMF v3 TC-21.
MCP vs A2A Attack Surface Comparative threat model — where MCP and Agent-to-Agent diverge in trust boundaries.
The 30% Blind Spot LLM-as-judge safety classifiers miss ~30% of adversarial output classes.
AI Breach Detection Gap Detection blind spots in AI-integrated production systems.
AI Coding Agent Attack Surface Attack surface analysis of AI-powered coding assistants and their tool-use capabilities.
Agentic AI Threat Landscape Threat landscape survey of autonomous AI agent architectures.
Adversarial Prompting: Complete Guide End-to-end methodology — direct, indirect, multi-turn, and agentic prompt injection.
Computational Countertransference The psychology of human–AI manipulation dynamics.
AATMF v3.1 vs MITRE ATLAS Framework comparison — coverage gaps in existing AI threat taxonomies.
The Memory Manipulation Problem How attackers exploit persistent context to compromise future interactions.
ChatGPT Canvas DNS Exfiltration DNS exfil via ChatGPT Canvas — rendered content triggers DNS lookups without outbound HTTP.
ChatGPT Sandbox RCE + DNS Exfil Pickle deserialization RCE chained with DNS exfiltration to escape Code Interpreter sandbox.
Double AI, Triple Mechanism Cloud-based obfuscator attack research.
Linux Kernel io_uring/zcrx Race Condition Race condition → double-free → OOB write in io_uring zero-copy receive. Mainlined; CVE-2026-43121.

sources of record: Wordfence · GHSA Credit · GitHub · lore.kernel.org


snailsploit

same attack. different substrate.

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors