Skip to content
winfunc
Backed byCombinator22 CVEs across 25 open-source projects

Security that keeps up with engineering.

Autonomous AI security agents that audit your codebase, prove what is exploitable, and hand your engineers the fix as a pull request.

Scoped with you. Delivered with evidence.

Download product overview
Proof
attached to every finding
Patch
opened as a pull request
SOC 2
Type II audited
Why winfunc

Less triage. More proof. Every finding comes with a code trace, an isolated reproduction, and a fix.

How it works

Every finding shows its work.

Follow a real disclosure, Ray Serve's unauthenticated gRPC deserialization (CVSS 9.8), from first signal to merged fix.

  1. 01

    Map the attack surface

    Agents index the repository, resolve the call graph, and mark every place untrusted input can enter.

  2. 02

    Follow the data

    From the source, the value is traced through each function that touches it, with the code recorded at every hop.

  3. 03

    Reach the sink

    The path ends at a dangerous operation with no check in between. That is a candidate, not yet a finding.

  4. 04

    Prove it

    Winfunc reproduces the exploit in an isolated environment and attaches the evidence. Unproven impact is labeled as such.

  5. 05

    Ship the fix

    A patch written in your codebase's own style opens as a pull request for your engineers to review.

  6. 06

    Verify the fix

    After the change, the proof runs again. The finding closes only when the exploit stops working.

  1. ray-project
  2. /ray
  3. /Vulnerabilities
  4. /Serve gRPC
Fixed · verified

Unauthenticated Serve replica gRPC requests allow arbitrary code execution

CriticalCVSS 9.8
Sourceprotobuf/serve.proto:525
ASGIRequest.pickled_request_metadata
1
Each initialized Python Serve replica created a raw asynchronous gRPC server outside Ray's authentication factory.self._server = grpc.aio.server(options=grpc_options)replica.py:Replica.__init__()
2
The internal service was exposed on an all-interface ephemeral port without TLS or token interception.port = self._server.add_insecure_port("[::]:0")replica.py:_on_initialized()
Sink · deserializationreplica.py:248
request_metadata = pickle.loads(request.pickled_request_metadata)
Reproduction · isolated clusterExploitable
  1. Environment
    isolated Ray cluster · RAY_AUTH_MODE=token
  2. Request
    ASGIService RPC sent without the Ray token
  3. Payload
    harmless proof reduction in pickled_request_metadata
  4. Observed
    marker written before metadata validation
ray-project/ray · PR #65189Merged Aug 5
python/ray/serve/_private/replica.py+4−2
−self._server = grpc.aio.server(options=options)
−self._server.add_insecure_port("[::]:0")
+self._server = create_grpc_server_with_interceptors(
+ asynchronous=True, options=options
+)
+add_port_to_grpc_server(self._server, address)
Re-run after fix · isolated clusterNot exploitable
  1. Environment
    isolated Ray cluster · RAY_AUTH_MODE=token
  2. Request
    ASGIService RPC sent without the Ray token
  3. Payload
    harmless proof reduction in pickled_request_metadata
  4. Observed
    request rejected before deserialization
Finding · RayPublic disclosure
Platform

One agent, the whole security workflow.

Start with a focused audit, keep every pull request covered, and ask the questions scanners can't. The same application context carries through each step.

All capabilities
AuditAvailable
  1. acme
  2. /billing-api
  3. /Vulnerabilities
Search findingsStatus Open
42 open
SeverityFinding
C9.1
Cross-tenant invoice read through an unscoped lookupAccess controlservices/invoices.ts:42
H8.1
Admin export reachable without a role checkAuthorizationroutes/admin/export.ts:18
H7.5
Webhook preview fetches internal addressesSSRFwebhooks/preview.ts:61
M6.5
Refresh token accepted without an audience checkAuthenticationauth/refresh.ts:27
Vulnerabilities · audit resultsIllustrative data

Security audit

A version-bound review of the whole codebase. Every finding is tied to the revision, traced to the line, and proven where testing is in scope.

Explore
Pull requestsAvailable
routes/admin/export.ts+3−0
10+router.get(
11+ "/admin/export",
winfuncHNo role check on an admin route. Reproduced with a member account.
12+ async (req, res) => {

Continuous code security

Diff-scoped review on every pull request, with suggested patches and an explicit re-review once the code changes.

Explore
QuestionsAvailable
Question

Can one tenant read another tenant's invoices?

Holds3 paths checked
Breaks1 path · proof

Hypothesis scans

Ask a security question in plain words. Get the paths that hold, the ones that break, and the proof.

Explore
DependenciesAvailable
  • express4.19.2
  • axios1.6.01.7.4
  • follow-redirects1.15.4
  • pdfkit0.13.0
Called fromwebhooks/preview.ts:61

Supply chain security

Reachability-aware SCA with SBOMs, license checks, and upgrade paths for your package manager.

Explore
EditorsAvailable
Editor agentmcp

# before you push

winfunc.review_change(diff)

! high token compared without constant time

fix: hmac.compare_digest(a, b)

Winfunc MCP

Security review inside Cursor, Claude Desktop, Windsurf, and Cline, before code leaves the laptop.

Explore
The cost of unproven alerts

Triage is where security time disappears.

Reproducing an issue and proving its impact is the expensive part of security work. Run your own numbers.

winfunc findings arrive with the trace, the reproduction, and the patch attached, so review starts from evidence instead of a hunch.

Your queue

30
20 min
$100

An estimate from your inputs, calculated across 52 weeks. It counts confirmation time only, before any fix is written.

43

engineering hours a month

65

engineer-days a year

$52K

a year spent confirming alerts

Workdays spent confirming alerts65 / 260
Track record

Real findings, in software you already run.

winfunc's agents have found and responsibly disclosed vulnerabilities in NGINX, Chromium, Node.js, React, and dozens of widely deployed projects. The record is public and verifiable.

Explore findings
Public disclosures
0
CVE IDs assigned
0
Open-source projects
0
Critical or high
0
Research · Jul 2026Six NGINX vulnerabilities, found with open modelsFive CVE IDs credited in F5's NGINX advisories, found with GLM models on Winfunc's harness.Read the research

N-Day-Bench · Apr 2026

Leaderboard

Our monthly benchmark of frontier models on real vulnerabilities disclosed after their training cutoff.

GPT-5.4
83.9
GLM-5.1
80.1
Claude Opus 4.6
80.0
Kimi K2.5
77.2
Gemini 3.1 Pro
68.5

Selected disclosures

All 48
SeverityProjectFindingReference
HighNGINXStream complex-value capture desynchronization causes heap overflowCVE-2026-42533
HighChromiumType Confusion in V8 (details withheld)CVE-2026-10910
CriticalRayUnauthenticated Serve replica gRPC requests allow arbitrary code executionDisclosed
Criticalserovalseroval.fromJSON() Promise resolver type confusion invokes attacker-controlled methodsCVE-2026-59940
CriticalAnthropicAuthentication bypass on FastMCP custom routesDisclosed
CriticalSupabaseSQL Injection via queueName in getDatabaseQueuesMetricsDisclosed
CriticalGumroad0-click Account Takeover and Admin Operations via helper endpoint authorization bypassDisclosed
HighReactRSC reply decoder DoS via $K FormData amplificationCVE-2026-23864
MediumNode.jsPermission model bypass via unchecked Unix Domain Socket connectionsCVE-2026-21636
HighMattermostGroup syncable scheme_admin authorization bypassCVE-2026-7387

Every public entry includes the affected code, the trace, reproduction conditions, and remediation.

Integrations

Works where your engineers already work.

Connect source control, pipelines, ticketing, chat, and AI editors. Findings land where decisions get made.

Source control
GitHub, GitLab, Bitbucket, Azure DevOps
CI/CD
GitHub Actions, Jenkins, CircleCI
Tickets and alerts
Jira, Slack, Microsoft Teams
AI editors via MCP
Cursor, Claude Desktop, Windsurf, Cline
All integrations
Source controlAI editors · MCP
GitHub
GitHub
GitLab
GitLab
Bitbucket
Bitbucket
Azure DevOps
Azure DevOps
GitHub Actions
GitHub Actions
Jenkins
Jenkins
CircleCI
CircleCI
Jira
Jira
Slack
Slack
Microsoft Teams
Microsoft Teams
Cursor
Cursor
Claude Desktop
Claude Desktop
Windsurf
Windsurf
Cline
Cline
Imagewinfunc
CI/CDTickets · alerts
Enterprise-ready

Built for the security review before the security review.

Single sign-on, zero data retention, customer-controlled deployment, and a complete audit trail. The controls your security and procurement teams ask for are already in place.

Enterprise plans

Identity and access

  • SAML 2.0 single sign-on

    Sign in through Okta, Microsoft Entra ID, Google Workspace, or any SAML 2.0 identity provider.

  • Federated login and provisioning

    Manage who gets access from the identity provider you already run.

  • Repository-scoped roles

    Owners decide who sees findings and who can run scans on each repository.

  • Revocable access keys

    API and MCP keys are stored only as SHA-256 hashes and can be revoked at any time.

Data protection

  • Zero data retention

    Source code is analyzed in ephemeral workspaces and deleted after each scan. Only findings are kept.

  • No training on your code

    Customer code and data are never used to train AI models.

  • Sealed credentials

    TLS on every connection. Test credentials are encrypted with per-record XChaCha20-Poly1305 keys.

  • Secret-free logs

    Logs keep request metadata only: never bodies, tokens, cookies, or authorization headers.

Deployment and models

  • Customer-controlled hostingEnterprise

    Run winfunc inside your own cloud or private environment.

  • Isolated tenantsEnterprise

    Dedicated single-tenant environments for regulated workloads.

  • Bring your own model keysEnterprise

    Route analysis through your own AI provider accounts and agreements.

  • Open-weight model support

    Proven in public research: the NGINX work behind five CVE IDs ran on open GLM models.

Oversight

  • Complete audit trail

    Every API request and authorization decision is logged for administrative review.

  • Least-privilege access

    winfunc reads only the repositories you select and never merges to protected branches.

  • Policy controls

    Repository rules set what each scan focuses on and reports, with organization-wide policies on Enterprise.

  • Named supportEnterprise

    A named security contact with contracted response terms.

AICPA SOC 2 Type II

SOC 2 Type II audited

Trust Center

Standard contract terms

  • Customer owns its code, findings, and delivered patches
  • Security incident notice within 72 hours
  • Customer data deleted within 30 days of termination
  • Data Processing Addendum for personal data
  • HIPAA Business Associate Agreement for PHI
  • Subprocessors bound by security obligations
Customers

What engineering leaders say.

“There were vulnerabilities that we thought we took care of that the Winfunc agent found extremely complex bypasses for, vulnerabilities that other security tools never would have found. The thorough proof of concept and replication instructions it generates make it super easy to confirm the vulnerability, fix it, and confirm the fix is secure.”
ImageNoahCo-Founder & CEO · ScoutScout
“We've worked with third party penetration testers in the past, but I love that Winfunc can protect us with continuous vulnerability scanning instead of saying goodbye after a one-time engagement.”
ImageDennisCo-Founder & CEO · SurgeSurge
“Winfunc had a seamless onboarding experience. I was able to get a detailed scan in less than a day and our engineering team were excited to see and fix the findings.”
ImageRamCo-Founder · SeiSei
“For a company like us where security is the top priority, having a platform like Winfunc to catch these issues early before they impact the broader ecosystem is a huge plus.”
ImageBereket EngidaFounder · Better AuthBetter Auth
FAQ

Questions, answered.

01What languages does winfunc support?

winfunc is not tied to a single rule set. It combines parsers, language servers, and model-assisted analysis, and its public findings already span C, C++, Go, Rust, Python, TypeScript, PHP, Ruby, and Lua codebases. Share a representative repository and we will confirm depth for your stack before an audit.

02How does winfunc keep false positives out of the report?

Every candidate is traced from source to sink and checked against the controls on that path. Where testing is in scope, winfunc reproduces the exploit in an isolated environment and attaches the evidence. Anything it could not establish is labeled as inference, so your team reviews a short list of supported findings instead of a queue of alerts.

03Can winfunc find business-logic vulnerabilities?

Yes. winfunc investigates roles, permissions, tenant boundaries, transactions, and state changes, which is where many of its public findings live: cross-tenant account takeovers, authorization bypasses, and payment logic flaws that pattern-based scanners do not model.

04How is this different from a penetration test?

They work well together. A pentest brings human judgment to an agreed, point-in-time scope. winfunc adds full codebase context and keeps investigating as the code changes, on every pull request and on a schedule, so coverage does not end when the engagement does.

05Where does our source code go?

winfunc reads only the repositories you select. Code is analyzed in ephemeral workspaces under zero data retention and deleted after each scan; only findings are kept. Customer code is never used to train AI models, and Enterprise customers can run winfunc in their own environment with their own model keys.

06Is winfunc ready for enterprise security review?

Yes. winfunc is SOC 2 Type II audited and supports SAML single sign-on, federated provisioning, repository-scoped roles, a complete audit trail, and zero data retention. Enterprise plans add customer-controlled hosting, isolated tenants, bring-your-own model keys, and named support. Documentation is available in the Trust Center.

07What is an AI security platform?

An AI security platform uses AI agents to do the work of a security engineer: read the codebase, find vulnerabilities, prove they are exploitable, and fix them. winfunc covers application code (SAST), dependencies (SCA), infrastructure as code, secrets, and containers, and extends into threat modeling, cloud security, and AI penetration testing.

08Can AI do penetration testing?

Yes, when it is held to an evidence bar. winfunc's agents read the source code, map the attack surface, chain weaknesses, and reproduce exploits in isolated environments before reporting them. Human testers stay valuable for judgment and scope; winfunc gives them full code context and keeps testing between engagements.

09How is winfunc different from traditional SAST tools?

Rule-based SAST matches code patterns and leaves your team to triage the noise. winfunc follows attacker-controlled input through the application to the operation it reaches, proves exploitability, and ships the fix as a pull request, so each finding arrives as a decision instead of an alert.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.