Security Research

These vulnerabilities were discovered by sv-agent, a CLI-based agentic harness that monitors source code changes and routes security-relevant diffs through specialized detectors. sv-agent is closed source and part of the SecureVibes Platform. Interested in trying it out? Get in touch.

Core Contributors: Anshuman Bhartiya · Harish Kolla

10CVEs
4GHSA Advisories
20Responsible Disclosures
$3,610Bounties Earned
12Programs Targeted

Responsible Disclosure (VDP)

20coordinated disclosures, CVEs & advisories
criticalLangflowCVE-2026-10140Aug 2026

One tenant's API key served everyone's voice traffic

FixedWrite-upFound by: Harish Kolla
highHashiCorp VaultCVE-2026-14886Aug 2026

Cross-namespace deletion of identity entities

FixedWrite-upFound by: Harish Kolla
criticalHome AssistantCVE-2026-64824Jul 2026

Backup restore allowed root code execution

FixedWrite-upFound by: Harish Kolla
criticalHome AssistantCVE-2026-64825Jul 2026

Pre-auth backup upload wrote files as root

FixedWrite-upFound by: Harish Kolla
lowHome AssistantCVE-2026-64823Jul 2026

Stored XSS in Shelly media player

FixedCVE RecordFound by: Harish Kolla
TailscalePR #20561Jul 2026

Unsigned peers kept capabilities under tailnet lock

Credited · Fixed upstreamWrite-upFound by: Harish Kolla
OpenAIissue #3516Jul 2026

Azure API key forwarded across redirects

Public report · Awaiting triageView reportFound by: Harish Kolla
OpenAIissue #521Jul 2026

Local user could hijack Codex IPC

Public report · Awaiting triageView reportFound by: Harish Kolla
Tailscaleissue #20352Jul 2026

Handshake race could crash the DERP relay

Public report · Fixed upstreamView reportFound by: Harish Kolla
mediumOpenClawGHSA-jvm4-4j77-39p6Jul 2026

QQBot streaming command could mutate config without explicit allowFrom

FixedGitHub AdvisoryFound by: Anshuman Bhartiya
mediumOpenClawGHSA-grc3-2j34-p6gmJul 2026

message.action forwarding could send Gateway credentials to model-supplied loopback URLs

FixedGitHub AdvisoryFound by: Anshuman Bhartiya
mediumOpenClawGHSA-6c4r-g249-wv3cJul 2026

Sandboxed session spawn could expose the real workspace path to child prompts

FixedGitHub AdvisoryFound by: Anshuman Bhartiya
highn8nCVE-2026-54305Jun 2026

Cross-tenant credential takeover

FixedWrite-upFound by: Harish Kolla
highHome AssistantCVE-2026-54317May 2026

Unauthenticated read of alarm-panel state

FixedWrite-upFound by: Harish Kolla
highOpenClawCVE-2026-59261May 2026

Workspace .env overrode provider credentials

FixedWrite-upFound by: Harish Kolla
highFrigateCVE-2026-54652May 2026

Viewer logs exposed admin credentials

FixedWrite-upFound by: Harish Kolla
HashiCorp VaultPR #32004May 2026

ACME race issued duplicate certificates

Patch submitted · Closed, not mergedView reportFound by: Harish Kolla
Apache AirflowPR #67628May 2026

Task-reschedule route skipped ti:self check

Credited · Fixed upstreamWrite-upFound by: Harish Kolla
Apache AirflowPR #66751May 2026

Hive stats operator interpolated SQL values

Fix requested · PR openView reportFound by: Harish Kolla
mediumOpenClawCVE-2026-43574GHSA-49cg-279w-m73xApr 2026

Empty approver lists could grant explicit approval authorization

FixedGitHub AdvisoryFound by: Anshuman Bhartiya

Bug Bounty Programs

Non-Disclosed3bounty awarded, pending public disclosure
mediumGitLab$1,160 bountyJun 2, 2026

Authorization bypass in AI feature

Resolved · pending disclosureFound by: Anshuman Bhartiya
Anthropic$350 bountyJun 2026

Credential disclosure

Bounty awarded · fix pendingFound by: Harish Kolla
Anthropic$100 bountyMay 8, 2026

Code Injection

Triaged · partial bountyFound by: Anshuman Bhartiya

Only publicly disclosed and paid findings are itemized here. Coordinated disclosures are linked to their advisory, CVE, or upstream report; bug-bounty findings awaiting public disclosure show an abstract description only.