Continuous Security Testing Platform
AI-driven agents that autonomously pentest, review code, verify exploits,
and auto-fix vulnerabilities.
Cerberus is an AI-powered security platform built by Ledger Donjon that continuously tests your infrastructure and codebase for vulnerabilities. Instead of one-off manual pentests, Cerberus deploys autonomous AI agents that explore, analyze, verify, and remediate security issues — then report back with structured findings and evidence.
A sample of security issues Cerberus has reported to upstream maintainers. We commit to responsible disclosure: when a finding is realistically exploitable, we report it privately through the project's security channel and follow their coordinated-disclosure process before any public mention. For lower-impact issues, we open a public issue or pull request directly so the conversation happens openly with maintainers.
| Project | Date | Vulnerability | Severity | Reference |
|---|---|---|---|---|
| Envoy Gateway | 2026-06-05 | Path-normalization bypass in EnvoyExtensionPolicy Lua enables arbitrary file read of K8s SA tokens and TLS certs |
Critical (CVSS 9.1) | CVE-2026-53713 |
| Envoy Gateway | 2026-06-05 | Unauthenticated xDS SotW access leaks TLS keys and routing config in GatewayNamespaceMode | High (CVSS 7.4) | CVE-2026-53714 |
| Sandboxie-Plus | 2026-05-22 | APC injection sandbox escape via unvalidated GuiServer hook registration |
High (CVSS 7.7) | CVE-2026-45313 |
| Clawvisor | 2026-04-24 | Cross-tenant adapter overwrite in generated adapter installation | Critical | PR #302 |
| Yubico (libfido2, python-fido2, YubiKey Manager) | 2026-04-15 | DLL search-path hijack on Windows | High (CVSS 7.0) | CVE-2026-40947 |
| KDE Kleopatra | 2026-04-08 | Local privilege escalation on Windows via single-instance mechanism | High | CVE-2026-41527 |
| Nethermind | 2026-04-03 | Duplicate-signature quorum bypass in XDC vote aggregation | Critical | PR #11027 |
| Wasabi Wallet | 2026-03-16 | OS command injection in URL opener via crafted "Read More" link | High | Issue #14410 |
| BTCPay Server | 2026-03-13 – 03-15 | 6 access-control & tampering issues — IDOR, cross-store/cross-tenant escalation, plan/price tampering | High–Critical | Commits |
Built by Ledger Donjon — the security research team at Ledger
