Security Research
These vulnerabilities were discovered by sv-agent, a CLI-based agentic harness that monitors source code changes and routes security-relevant diffs through specialized detectors. sv-agent is closed source and part of the SecureVibes Platform. Interested in trying it out? Get in touch.
Core Contributors: Anshuman Bhartiya · Harish Kolla
10CVEs
4GHSA Advisories
20Responsible Disclosures
$3,610Bounties Earned
12Programs Targeted
Responsible Disclosure (VDP)
20coordinated disclosures, CVEs & advisoriescriticalLangflowCVE-2026-10140Aug 2026
One tenant's API key served everyone's voice traffic
highHashiCorp VaultCVE-2026-14886Aug 2026
Cross-namespace deletion of identity entities
criticalHome AssistantCVE-2026-64824Jul 2026
Backup restore allowed root code execution
criticalHome AssistantCVE-2026-64825Jul 2026
Pre-auth backup upload wrote files as root
lowHome AssistantCVE-2026-64823Jul 2026
Stored XSS in Shelly media player
TailscalePR #20561Jul 2026
Unsigned peers kept capabilities under tailnet lock
OpenAIissue #3516Jul 2026
Azure API key forwarded across redirects
OpenAIissue #521Jul 2026
Local user could hijack Codex IPC
Tailscaleissue #20352Jul 2026
Handshake race could crash the DERP relay
mediumOpenClawGHSA-jvm4-4j77-39p6Jul 2026
QQBot streaming command could mutate config without explicit allowFrom
mediumOpenClawGHSA-grc3-2j34-p6gmJul 2026
message.action forwarding could send Gateway credentials to model-supplied loopback URLs
mediumOpenClawGHSA-6c4r-g249-wv3cJul 2026
Sandboxed session spawn could expose the real workspace path to child prompts
highn8nCVE-2026-54305Jun 2026
Cross-tenant credential takeover
highHome AssistantCVE-2026-54317May 2026
Unauthenticated read of alarm-panel state
highOpenClawCVE-2026-59261May 2026
Workspace .env overrode provider credentials
highFrigateCVE-2026-54652May 2026
Viewer logs exposed admin credentials
HashiCorp VaultPR #32004May 2026
ACME race issued duplicate certificates
Apache AirflowPR #67628May 2026
Task-reschedule route skipped ti:self check
Apache AirflowPR #66751May 2026
Hive stats operator interpolated SQL values
mediumOpenClawCVE-2026-43574GHSA-49cg-279w-m73xApr 2026
Empty approver lists could grant explicit approval authorization
Bug Bounty Programs
Non-Disclosed3bounty awarded, pending public disclosure
mediumGitLab$1,160 bountyJun 2, 2026
Authorization bypass in AI feature
Anthropic$350 bountyJun 2026
Credential disclosure
Anthropic$100 bountyMay 8, 2026
Code Injection
Only publicly disclosed and paid findings are itemized here. Coordinated disclosures are linked to their advisory, CVE, or upstream report; bug-bounty findings awaiting public disclosure show an abstract description only.