BugTraceAI: open-source self-hosted agentic pentester with three CVEs
BugTraceAI is an open-source, self-hosted Apache-2.0 framework for authorized bug bounty and penetration testing. AI agents drive a six-phase pipeline (recon, discovery, strategy, exploit, validate, report) while deterministic tools verify findings. Three CVEs rated 7.2–8.8 have been disclosed so far.
- Six-phase pipeline: recon, discovery, strategy, exploit, validate, report
- CVEs found: CVE-2026-27479 (Wallos, 7.7), CVE-2026-27470 (ZoneMinder, 8.8), CVE-2026-27834 (Piwigo, 7.2)
- Components: CLI, WEB with 20+ security tools, API and Launcher; fully self-hosted
- BugStore practice target ships 32 planted OWASP vulnerabilities
Read next
Security