Security that keeps up with engineering.
Autonomous AI security agents that audit your codebase, prove what is exploitable, and hand your engineers the fix as a pull request.
- Proof
- attached to every finding
- Patch
- opened as a pull request
- SOC 2
- Type II audited
- HNGINXStream complex-value capture desynchronization causes heap overflowCVE-2026-42533
- Cserovalseroval.fromJSON() Promise resolver type confusion invokes attacker-controlled methodsCVE-2026-59940
- HNGINXgRPC forwarded headers can overflow the upstream HPACK request bufferCVE-2026-42055
- HNGINXHTTP/2 upstream proxy request encoder permits heap overflow with oversized raw headersCVE-2026-42055
- HChromiumType Confusion in V8CVE-2026-10910
- MChromiumUninitialized Use in ANGLECVE-2026-10994
- MChromiumInteger overflow in ANGLECVE-2026-10019
- HNGINXrewrite overlapping captures heap overflowCVE-2026-9256
- MNGINXHTTP/2 upstream frame injection via oversized proxy_set_bodyCVE-2026-42926
- MNGINXstream accepts revoked client certificates despite ssl_ocsp onCVE-2026-28755
- MNGINXSCGI unbuffered mode sent truncated CONTENT_LENGTH causing backend desync
- HNGINXWebDAV COPY/MOVE path overlap corrupts files and collections
- HReactRSC reply decoder DoS via $K FormData amplificationCVE-2026-23864
- MNode.jsPermission model bypass via unchecked Unix Domain Socket connectionsCVE-2026-21636
- CAnthropicAuthentication bypass on FastMCP custom routes
- CSupabaseSQL Injection via queueName in getDatabaseQueuesMetrics
- HBunExponential merge keys in Bun's YAML implementation leads to DoS
- CGumroad0-click Account Takeover and Admin Operations via helper endpoint authorization bypass
- MMattermostRemote cluster PATCH response leaked authentication tokensCVE-2026-7184
- HMattermostGroup syncable scheme_admin authorization bypassCVE-2026-7387
- HMattermostmmctl terminal escape injection via unsanitized server-controlled outputCVE-2026-3108
- MMattermostZip bomb memory exhaustion in recursive document extractionCVE-2026-3114
- MMattermostGroup member IDs leaked because GetGroup bypassed view restrictionsCVE-2026-3115
- MMattermostmmctl export downloads created world-readable local filesCVE-2026-3113
- MMattermostPrivate channel enumeration through /mute error messagesCVE-2026-21386
- HMattermostOversized password login DoS in legacy password comparisonCVE-2026-24458
- MMattermostUser-Agent version parser panic during session creationCVE-2026-25783
- MMattermostSSRF protection bypass via IPv4-mapped IPv6 literalsCVE-2026-2455
Less triage. More proof. Every finding comes with a code trace, an isolated reproduction, and a fix.
Every finding shows its work.
Follow a real disclosure, Ray Serve's unauthenticated gRPC deserialization (CVSS 9.8), from first signal to merged fix.
- 01
Map the attack surface
Agents index the repository, resolve the call graph, and mark every place untrusted input can enter.
- 02
Follow the data
From the source, the value is traced through each function that touches it, with the code recorded at every hop.
- 03
Reach the sink
The path ends at a dangerous operation with no check in between. That is a candidate, not yet a finding.
- 04
Prove it
Winfunc reproduces the exploit in an isolated environment and attaches the evidence. Unproven impact is labeled as such.
- 05
Ship the fix
A patch written in your codebase's own style opens as a pull request for your engineers to review.
- 06
Verify the fix
After the change, the proof runs again. The finding closes only when the exploit stops working.
- ray-project
- /ray
- /Vulnerabilities
- /Serve gRPC
Unauthenticated Serve replica gRPC requests allow arbitrary code execution
self._server = grpc.aio.server(options=grpc_options)replica.py:Replica.__init__()port = self._server.add_insecure_port("[::]:0")replica.py:_on_initialized()- Environmentisolated Ray cluster · RAY_AUTH_MODE=token
- RequestASGIService RPC sent without the Ray token
- Payloadharmless proof reduction in pickled_request_metadata
- Observedmarker written before metadata validation
| −self._server = grpc.aio.server(options=options) | ||
| −self._server.add_insecure_port("[::]:0") | ||
| +self._server = create_grpc_server_with_interceptors( | ||
| + asynchronous=True, options=options | ||
| +) | ||
| +add_port_to_grpc_server(self._server, address) |
- Environmentisolated Ray cluster · RAY_AUTH_MODE=token
- RequestASGIService RPC sent without the Ray token
- Payloadharmless proof reduction in pickled_request_metadata
- Observedrequest rejected before deserialization
One agent, the whole security workflow.
Start with a focused audit, keep every pull request covered, and ask the questions scanners can't. The same application context carries through each step.
- acme
- /billing-api
- /Vulnerabilities
| Severity | Finding |
|---|---|
| C9.1 | Cross-tenant invoice read through an unscoped lookupAccess controlservices/invoices.ts:42 |
| H8.1 | Admin export reachable without a role checkAuthorizationroutes/admin/export.ts:18 |
| H7.5 | Webhook preview fetches internal addressesSSRFwebhooks/preview.ts:61 |
| M6.5 | Refresh token accepted without an audience checkAuthenticationauth/refresh.ts:27 |
Security audit
A version-bound review of the whole codebase. Every finding is tied to the revision, traced to the line, and proven where testing is in scope.
Explore| 10 | +router.get( | |
| 11 | + "/admin/export", | |
winfuncHNo role check on an admin route. Reproduced with a member account. | ||
| 12 | + async (req, res) => { | |
Continuous code security
Diff-scoped review on every pull request, with suggested patches and an explicit re-review once the code changes.
ExploreCan one tenant read another tenant's invoices?
Hypothesis scans
Ask a security question in plain words. Get the paths that hold, the ones that break, and the proof.
Explore- express4.19.2
- axios1.6.01.7.4
- follow-redirects1.15.4
- pdfkit0.13.0
Supply chain security
Reachability-aware SCA with SBOMs, license checks, and upgrade paths for your package manager.
Explore# before you push
winfunc.review_change(diff)
! high token compared without constant time
fix: hmac.compare_digest(a, b)
Winfunc MCP
Security review inside Cursor, Claude Desktop, Windsurf, and Cline, before code leaves the laptop.
ExploreTriage is where security time disappears.
Reproducing an issue and proving its impact is the expensive part of security work. Run your own numbers.
winfunc findings arrive with the trace, the reproduction, and the patch attached, so review starts from evidence instead of a hunch.
Your queue
An estimate from your inputs, calculated across 52 weeks. It counts confirmation time only, before any fix is written.
43
engineering hours a month
65
engineer-days a year
$52K
a year spent confirming alerts
Real findings, in software you already run.
winfunc's agents have found and responsibly disclosed vulnerabilities in NGINX, Chromium, Node.js, React, and dozens of widely deployed projects. The record is public and verifiable.
N-Day-Bench · Apr 2026
LeaderboardOur monthly benchmark of frontier models on real vulnerabilities disclosed after their training cutoff.
- GPT-5.4
- 83.9
- GLM-5.1
- 80.1
- Claude Opus 4.6
- 80.0
- Kimi K2.5
- 77.2
- Gemini 3.1 Pro
- 68.5
Selected disclosures
All 48| Severity | Project | Finding | Reference |
|---|---|---|---|
| High | NGINX | Stream complex-value capture desynchronization causes heap overflow | CVE-2026-42533 |
| High | Chromium | Type Confusion in V8 (details withheld) | CVE-2026-10910 |
| Critical | Ray | Unauthenticated Serve replica gRPC requests allow arbitrary code execution | Disclosed |
| Critical | seroval | seroval.fromJSON() Promise resolver type confusion invokes attacker-controlled methods | CVE-2026-59940 |
| Critical | Anthropic | Authentication bypass on FastMCP custom routes | Disclosed |
| Critical | Supabase | SQL Injection via queueName in getDatabaseQueuesMetrics | Disclosed |
| Critical | Gumroad | 0-click Account Takeover and Admin Operations via helper endpoint authorization bypass | Disclosed |
| High | React | RSC reply decoder DoS via $K FormData amplification | CVE-2026-23864 |
| Medium | Node.js | Permission model bypass via unchecked Unix Domain Socket connections | CVE-2026-21636 |
| High | Mattermost | Group syncable scheme_admin authorization bypass | CVE-2026-7387 |
Every public entry includes the affected code, the trace, reproduction conditions, and remediation.
Works where your engineers already work.
Connect source control, pipelines, ticketing, chat, and AI editors. Findings land where decisions get made.
- Source control
- GitHub, GitLab, Bitbucket, Azure DevOps
- CI/CD
- GitHub Actions, Jenkins, CircleCI
- Tickets and alerts
- Jira, Slack, Microsoft Teams
- AI editors via MCP
- Cursor, Claude Desktop, Windsurf, Cline
winfuncBuilt for the security review before the security review.
Single sign-on, zero data retention, customer-controlled deployment, and a complete audit trail. The controls your security and procurement teams ask for are already in place.
Identity and access
SAML 2.0 single sign-on
Sign in through Okta, Microsoft Entra ID, Google Workspace, or any SAML 2.0 identity provider.
Federated login and provisioning
Manage who gets access from the identity provider you already run.
Repository-scoped roles
Owners decide who sees findings and who can run scans on each repository.
Revocable access keys
API and MCP keys are stored only as SHA-256 hashes and can be revoked at any time.
Data protection
Zero data retention
Source code is analyzed in ephemeral workspaces and deleted after each scan. Only findings are kept.
No training on your code
Customer code and data are never used to train AI models.
Sealed credentials
TLS on every connection. Test credentials are encrypted with per-record XChaCha20-Poly1305 keys.
Secret-free logs
Logs keep request metadata only: never bodies, tokens, cookies, or authorization headers.
Deployment and models
Customer-controlled hostingEnterprise
Run winfunc inside your own cloud or private environment.
Isolated tenantsEnterprise
Dedicated single-tenant environments for regulated workloads.
Bring your own model keysEnterprise
Route analysis through your own AI provider accounts and agreements.
Open-weight model support
Proven in public research: the NGINX work behind five CVE IDs ran on open GLM models.
Oversight
Complete audit trail
Every API request and authorization decision is logged for administrative review.
Least-privilege access
winfunc reads only the repositories you select and never merges to protected branches.
Policy controls
Repository rules set what each scan focuses on and reports, with organization-wide policies on Enterprise.
Named supportEnterprise
A named security contact with contracted response terms.
SOC 2 Type II audited
Trust Center
Standard contract terms
- Customer owns its code, findings, and delivered patches
- Security incident notice within 72 hours
- Customer data deleted within 30 days of termination
- Data Processing Addendum for personal data
- HIPAA Business Associate Agreement for PHI
- Subprocessors bound by security obligations
What engineering leaders say.
“There were vulnerabilities that we thought we took care of that the Winfunc agent found extremely complex bypasses for, vulnerabilities that other security tools never would have found. The thorough proof of concept and replication instructions it generates make it super easy to confirm the vulnerability, fix it, and confirm the fix is secure.”
NoahCo-Founder & CEO · Scout
“We've worked with third party penetration testers in the past, but I love that Winfunc can protect us with continuous vulnerability scanning instead of saying goodbye after a one-time engagement.”
DennisCo-Founder & CEO · Surge
“Winfunc had a seamless onboarding experience. I was able to get a detailed scan in less than a day and our engineering team were excited to see and fix the findings.”
RamCo-Founder · Sei
“For a company like us where security is the top priority, having a platform like Winfunc to catch these issues early before they impact the broader ecosystem is a huge plus.”
Bereket EngidaFounder · Better Auth
Research you can inspect.

Research
Finding six NGINX vulnerabilities with open models
We used GLM-5.1 and GLM-5.2 to scan NGINX. The scan produced six security findings with five CVE identifiers. This report describes the affected code, analysis traces, and proof conditions.
Mufeed VH16 min read

Research
Hacking the old HackerNews codebase
Auditing the old HackerNews codebase for security vulnerabilities with LLMs on a specialized harness.
Mufeed VH11 min read

Research
What an automated vulnerability research system actually found
Thirteen patched bugs across nine projects, including Node.js, React, NGINX, Mattermost, Supabase, Bun, Gumroad, Anthropic's MCP SDK, and Better-Auth. What the system got right, where it still falls over, and why executable PoCs matter more than model reasoning.
Mufeed VH8 min read
Questions, answered.
01What languages does winfunc support?
winfunc is not tied to a single rule set. It combines parsers, language servers, and model-assisted analysis, and its public findings already span C, C++, Go, Rust, Python, TypeScript, PHP, Ruby, and Lua codebases. Share a representative repository and we will confirm depth for your stack before an audit.
02How does winfunc keep false positives out of the report?
Every candidate is traced from source to sink and checked against the controls on that path. Where testing is in scope, winfunc reproduces the exploit in an isolated environment and attaches the evidence. Anything it could not establish is labeled as inference, so your team reviews a short list of supported findings instead of a queue of alerts.
03Can winfunc find business-logic vulnerabilities?
Yes. winfunc investigates roles, permissions, tenant boundaries, transactions, and state changes, which is where many of its public findings live: cross-tenant account takeovers, authorization bypasses, and payment logic flaws that pattern-based scanners do not model.
04How is this different from a penetration test?
They work well together. A pentest brings human judgment to an agreed, point-in-time scope. winfunc adds full codebase context and keeps investigating as the code changes, on every pull request and on a schedule, so coverage does not end when the engagement does.
05Where does our source code go?
winfunc reads only the repositories you select. Code is analyzed in ephemeral workspaces under zero data retention and deleted after each scan; only findings are kept. Customer code is never used to train AI models, and Enterprise customers can run winfunc in their own environment with their own model keys.
06Is winfunc ready for enterprise security review?
Yes. winfunc is SOC 2 Type II audited and supports SAML single sign-on, federated provisioning, repository-scoped roles, a complete audit trail, and zero data retention. Enterprise plans add customer-controlled hosting, isolated tenants, bring-your-own model keys, and named support. Documentation is available in the Trust Center.
07What is an AI security platform?
An AI security platform uses AI agents to do the work of a security engineer: read the codebase, find vulnerabilities, prove they are exploitable, and fix them. winfunc covers application code (SAST), dependencies (SCA), infrastructure as code, secrets, and containers, and extends into threat modeling, cloud security, and AI penetration testing.
08Can AI do penetration testing?
Yes, when it is held to an evidence bar. winfunc's agents read the source code, map the attack surface, chain weaknesses, and reproduce exploits in isolated environments before reporting them. Human testers stay valuable for judgment and scope; winfunc gives them full code context and keeps testing between engagements.
09How is winfunc different from traditional SAST tools?
Rule-based SAST matches code patterns and leaves your team to triage the noise. winfunc follows attacker-controlled input through the application to the operation it reaches, proves exploitability, and ships the fix as a pull request, so each finding arrives as a decision instead of an alert.
Bring us your hardest codebase.
We'll bring the proof.
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.
