adversarial ai research · llm red teaming · kernel · vulnerability research
same attack. different substrate.
snailsploit is an independent adversarial research group — vulnerability research, framework development, and offensive tooling across kernels, language models, and everything between them.
61 published CVEs · 3 linux kernel CVEs · 5 mainlined kernel patches · 27 distinct targets
snailsploit.com →
sorted by target class — infrastructure and AI first, then libraries, then CMS plugins. severity is the secondary sort within each tier.
#
CVE
Target
Type
Severity
Status
1
CVE-2026-47393
PraisonAI
Authentication disabled by default
Critical (9.8)
Published
2
CVE-2026-57127
PraisonAI
recipe serve auth middleware disables itself with no secret
Critical (9.8)
Published
3
CVE-2026-57131
PraisonAI
Jobs API exposes agent-execution endpoints with no auth
Critical (9.8)
Published
4
CVE-2026-57147
PraisonAI
Hardcoded default JWT signing secret enables token forgery
Critical (9.8)
Published
5
CVE-2026-47398
PraisonAI
Code injection via exec_module (YAML-controlled module paths)
High (8.1)
Published
6
CVE-2026-57126
PraisonAI
SSRF guard validates literal IPs only — never resolves DNS
High (8.5)
Published
7
CVE-2026-55528
PraisonAI
AgentServer declares auth_token but never enforces it on any route (CWE-862)
High (8.2)
Published
8
CVE-2026-57120
PraisonAI
execute_code sandbox bypass via str.format dunder access
Medium (6.5)
Published
9
CVE-2026-55530
PraisonAI
ast_grep_rewrite rewrites arbitrary files without @require_approval gate (CWE-862)
Moderate (6.1)
Published
10
CVE-2026-62164
PraisonAI
HITL tool approval cached by tool name — silently reused for subsequent calls with arbitrary arguments
—
CVE Assigned
11
CVE-2026-62171
PraisonAI
Prompt-injection defense blocks only when 3+ detector families fire simultaneously; single-vector injections pass through
—
CVE Assigned
12
CVE-2026-48814
Network AI
Empty default secret accepted → authentication bypass (CWE-287/1188)
High
Published
13
CVE-2026-54236
vLLM
Incomplete CVE-2026-22778 fix → PIL repr ASLR-bypass infoleak via Anthropic router (CWE-532)
Medium (5.3)
Published
14
CVE-2026-48782
pydantic-ai
SSRF — metadata blocklist bypass via IPv6 transition forms
Medium (6.8)
Published
#
CVE
Target
Type
Severity
Status
15
CVE-2026-43121
Linux Kernel io_uring/zcrx
user_ref race → double-free → OOB write
Medium (4.7)
Published
16
CVE-2026-46132
Linux Kernel net/rtnetlink
ifla_vf_broadcast stack infoleak via Netlink RTM_GETLINK
Low
Published
17
CVE-2026-53371
Linux Kernel RDMA/ionic
Unbounded %s in hca_type_show reads past node_desc[64] — userspace-triggerable OOB read via sysfs
—
Published
infrastructure & orchestration
#
CVE
Target
Type
Severity
Status
18
CVE-2026-3288
Kubernetes ingress-nginx
Config injection → RCE
High (8.8)
Published
19
CVE-2026-30911
Apache Airflow Core
Missing auth (HITL)
High (8.1)
Published
20
CVE-2026-32794
Apache Airflow (Databricks Provider)
TLS verification bypass → MitM
Medium (4.8)
Published
21
CVE-2026-55070
argoproj/argo-workflows
Informer-cache auth-bypass fix incomplete — Lint/Create resolve templates without per-caller auth (CWE-285)
Moderate (5.3)
CVE Assigned
22
CVE-2026-48130
tektoncd/pipeline
Hub resolver reads HTTP response body via unbounded io.ReadAll → OOM DoS (CWE-770)
Moderate (6.5)
CVE Assigned
#
CVE
Target
Type
Severity
Status
23
CVE-2026-57303
Jenkins Assembla plugin
XXE
High
Published
24
CVE-2026-57297
Jenkins Contrast CAS plugin
Missing permission check — connection-test → credential capture / SSRF
Medium
Published
25
CVE-2026-57299
Jenkins Contrast CAS plugin
Missing permission checks — metadata enumeration
Medium
Published
26
CVE-2026-57304
Jenkins Assembla plugin
Missing permission check
Medium
Published
27
CVE-2026-57298
Jenkins Contrast CAS plugin
CSRF
Medium
Published
28
CVE-2026-57305
Jenkins Assembla plugin
CSRF
Medium
Published
#
CVE
Target
Type
Severity
Status
29
CVE-2026-49853
tornadoweb/tornado
Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
High (7.7)
Published
30
CVE-2026-49353
decolua/9router
Incomplete fix for CVE-2026-46339 — local-only access gate bypass via Host header spoofing (CWE-290)
High (7.5)
Published
31
CVE-2026-31899
CairoSVG
Exponential DoS — recursive amplification
High (7.5)
Published
32
CVE-2026-44840
Dgraph
DQL injection via checkUserPassword GraphQL query
High
Published
33
CVE-2026-52775
yeswiki/yeswiki
Authenticated SQL injection via ReactionManager
High
Published
34
CVE-2026-32809
ouch (Rust)
Symlink escape
High (7.4)
NVD: RESERVED
35
CVE-2026-45363
jwt/ruby-jwt
Empty-key HMAC bypass
7.4
NVD: RESERVED
36
CVE-2026-48022
@hapi/wreck (npm)
Credential header leak on cross-port / cross-scheme redirect
Moderate
Published
37
CVE-2026-54171
Excon (RubyGems)
Sensitive/risky headers not redacted on redirect
Moderate
Published
38
CVE-2026-33693
activitypub-federation-rust
SSRF — 0.0.0.0 bypass
Medium (6.5)
Published
39
CVE-2026-32885
ddev/ddev
ZipSlip
Medium (6.5)
Published
40
CVE-2026-8368
Perl LWP::UserAgent / HTTP::Tiny
Zero header strip on cross-host redirect
—
NVD: RESERVED
41
CVE-2026-44217
sse-channel (npm)
SSE injection — unsanitized fields
Moderate
Published
42
CVE-2026-46627
Twig (PHP)
Sandbox resource exhaustion — CPU/memory DoS
Moderate
Published
#
CVE
Target
Type
Severity
Status
43
CVE-2026-43884
AVideo
SSRF protection bypass via DNS rebinding
High
Published
44
CVE-2026-43881
AVideo
Unauthenticated user enumeration via isCompany parameter
Medium (5.3)
Published
45
CVE-2026-45619
AVideo
CVE-2026-43884 incomplete fix — 6+ isSSRFSafeURL() call sites discard $resolvedIP out-param
—
Published
46
CVE-2026-45620
AVideo
CVE-2026-43881 incomplete fix
—
Published
#
CVE
Target
Type
Severity
Status
47
CVE-2026-3596
Riaxe Product Customizer
Missing auth → priv esc
Critical (9.8)
Published
48
CVE-2026-1313
MimeTypes Link Icons
SSRF
High (8.3)
Published
49
CVE-2026-3599
Riaxe Product Customizer
Unauthenticated SQLi
High (7.5)
Published
50
CVE-2025-9776
CatFolders
SQLi via CSV import
Medium (6.5)
Published
51
CVE-2025-12163
Omnipress
Stored XSS
Medium (6.4)
Published
52
CVE-2026-2717
HTTP Headers
CRLF injection
Medium (5.5)
Published
53
CVE-2026-0811
Advanced CF7 DB
CSRF → form deletion
Medium (5.4)
Published
54
CVE-2026-3594
Riaxe Product Customizer
Info disclosure — /orders
Medium (5.3)
Published
55
CVE-2026-3595
Riaxe Product Customizer
Unauthenticated user deletion
Medium (5.3)
Published
56
CVE-2026-1314
3D FlipBook
Missing auth
Medium (5.3)
Published
57
CVE-2025-11171
Chartify
Missing auth — admin function
Medium (5.3)
Published
58
CVE-2025-11174
Document Library Lite
Missing auth → info disclosure
Medium (5.3)
Published
59
CVE-2025-12030
ACF to REST API
IDOR
Medium (4.3)
Published
60
CVE-2026-0814
Advanced CF7 DB
Missing auth — subscriber+ export
Medium (4.3)
Published
61
CVE-2026-1208
Welcart
CSRF → settings update
Medium (4.3)
Published
five patches mainlined through the standard kernel maintainer process — three with assigned CVEs.
Subsystem
Fix
CVE
Status
io_uring/zcrx
Fix user_ref race between scrub and refill → double-free → OOB write
CVE-2026-43121
Mainlined 7.0-rc1
net/rtnetlink
Zero ifla_vf_broadcast to avoid stack infoleak
CVE-2026-46132
Mainlined
RDMA/ionic
Bound node_desc sysfs read with %.64s — unbounded %s OOB read
CVE-2026-53371
Mainlined
net/tipc
tipc_mon_peer_up/down/remove_peer UAF
—
Mainlined
Bluetooth/hci_conn
UAF in create_big_sync and create_big_complete
—
Mainlined
all patches on lore.kernel.org →
GHSAs, vendor findings & bounties
ID
Target
Type
Status
—
TelSender (WP)
Unauthenticated stored XSS via Telegram chat title (7.2)
Plugin taken down
GHSA-j425-whc4-4jgc
OpenClaw
system.run env override RCE — allowlist bypass (6.3)
Published
GHSA-gxhx-2686-5h9g
slack-go/slack
Security advisory
Published
GHSA-985r-q3qp-299h
phpmyfaq/phpmyfaq
Incomplete fix — editUser() and updateUserRights() lack auth guards
Published
—
@linear/sdk
LinearWebhooks.verify accepts empty secret without precondition
Merged ($400 bounty)
Project
Description
AATMF v3.1
Adversarial AI Threat Modeling Framework — 20 tactics, 240+ techniques, 2,152+ procedures, 4,980+ prompts. Crosswalks to OWASP LLM Top-10, NIST AI RMF, MITRE ATLAS, EU AI Act. On OWASP GenAI Security 2026 roadmap. YARA + Sigma detection signatures included.
AATMF Toolkit
Python CLI for systematic LLM safety testing — three-layer evaluation pipeline, defense fingerprinting, regression tracking, attack chain planning.
Claude-Red
58 offensive security skills across 13 categories for the Claude skills system. Drop a SKILL.md and Claude operates as a specialist — SQLi to shellcode, EDR evasion to ADCS abuse.
LLM Red Teamer's Playbook
Diagnostic methodology for bypassing LLM defense layers — input filters → alignment → identity → output → agentic trust.
Burp MCP Toolkit
Skills-based security analysis — Burp Suite traffic capture with Claude Code reasoning via MCP.
JystDastIt
The Burp You Can Afford — open-source CLI DAST toolkit.
SnailObfuscator
Structurally-aware code obfuscation engine — polymorphic payload generation.
SnailHunter
AI-powered bug bounty automation — LLM analysis + traditional scanning.
KubeRoast
Red-team Kubernetes misconfiguration & attack-path scanner.
Xposure
Autonomous credential intelligence platform for attack-surface recon.
SnailSploit Recon
Chrome MV3 extension — passive recon, security headers, IP intel, CPE→CVE enrichment.
Awesome-Snail-OSINT
Curated OSINT resource collection for offensive recon.
P.R.O.M.P.T
Adversarial prompt engineering methodology — structured attack phases with Cialdini influence principles.
SEF
Social Engineering Framework — organizational gap analysis, pretext selection, MITRE ATT&CK mapping.
published at snailsploit.com , Hakin9 Magazine , and Medium .
Metric
Count
Published / assigned CVEs
61
— critical
5
— high
18
Distinct targets
27
Mainlined linux kernel patches
5
Kernel CVEs
3
GHSAs / vendor disclosures / bounties
5
Published frameworks
3 (AATMF, SEF, P.R.O.M.P.T)
Open-source tools
11
cross-reference note: CVE-2026-43121, CVE-2026-46132, and CVE-2026-53371 each appear once in the CVE table and once in the kernel patches section — same finding, listed in both places for discoverability. CVE-2026-48022 (@hapi/wreck) appears once in the CVE table; its GHSA is the same finding.
sources of record: Wordfence · GHSA Credit · GitHub · lore.kernel.org
same attack. different substrate.