VulnGym: A Real-World, Project-Level Vulnerability Benchmark for White-Box Vulnerability-Hunting Agents
☆231Jun 26, 2026Updated last month
Alternatives and similar repositories for VulnGym
Users that are interested in VulnGym are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Claude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析☆140Mar 20, 2026Updated 4 months ago
- Self-contained, Dockerized offensive security challenges for evaluating AI-powered penetration testing agents. Covers modern tech stacks …☆55Jul 24, 2026Updated 3 weeks ago
- Hacking GraalVM Espresso - Abusing Continuation API to Make ROP-like Attack☆36Aug 27, 2025Updated 11 months ago
- The source code of [S&P'25] Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications.☆72Nov 20, 2025Updated 8 months ago
- My presentation slides☆18Oct 31, 2025Updated 9 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A AI general-purpose state-space search engine, validated first on autonomous penetration testing.☆2,320Jul 15, 2026Updated last month
- [IEEE S&P'26] WebCloak: Characterizing and Mitigating the Threats of LLM-Driven Web Agents as Intelligent Scrapers☆29Jan 31, 2026Updated 6 months ago
- 腾讯云智能渗透黑客松 Official repository of Tencent Cloud Intelligent Penetration Hackathon. Showcasing top open-source projects of LLM-based auton…☆766Jul 15, 2026Updated last month
- ☆210Oct 27, 2025Updated 9 months ago
- 智能渗透Agent Manager/Observer/Solver 多角色架构,基于 pi-mono SDK。☆491Aug 10, 2026Updated last week
- CyberGym is a large-scale, high-quality cybersecurity evaluation framework designed to rigorously assess the capabilities of AI agents on…☆740Aug 4, 2026Updated 2 weeks ago
- A data pool-aware static analyzer to detect cross-layer threats in Android apps.☆12Jan 31, 2024Updated 2 years ago
- A next-generation unified program analysis framework for semantic extraction and security validation, supporting any programming language…☆16Aug 11, 2026Updated last week
- An autonomous LLM-agent for large-scale, repository-level code auditing☆431Mar 12, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆15Jul 24, 2025Updated last year
- ☆31Sep 1, 2025Updated 11 months ago
- YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, d…☆312Updated this week
- YASA-UAST is an intermediate representation structure for multi-language program analysis. The UAST-Parser parses code from different pro…☆88Jul 6, 2026Updated last month
- 《深入理解CodeQL》Finding vulnerabilities with CodeQL.☆1,788Nov 21, 2023Updated 2 years ago
- The source code of [Sec'25] Make Agent Defeat Agent: Automatic Detection of Taint-Style Vulnerabilities in LLM-based Agents☆97Apr 13, 2026Updated 4 months ago
- 用于快速启动tabby 分析漏洞或者gadget的环境☆92Jul 14, 2025Updated last year
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆594Feb 7, 2026Updated 6 months ago
- 高版本Fastjson在Java原生反序列化中的利用演示☆26Jan 12, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- 东方隐侠团队出品,代码审计skill☆137Feb 25, 2026Updated 5 months ago
- 阿里巴巴安全SDK,提供SSRF、JDBC、XXE防护能力☆117Oct 15, 2025Updated 10 months ago
- A Java Route Collection Tool☆101Aug 1, 2024Updated 2 years ago
- A benchmark for Java gadget chain detecting algorithms.☆17Jun 20, 2025Updated last year
- CVE-Bench: A Benchmark for AI Agents’ Ability to Exploit Real-World Web Application Vulnerabilities☆271Jan 14, 2026Updated 7 months ago
- The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection …☆1,241Updated this week
- 利用代理驱动绕过JDBC Attack检测☆145Jun 15, 2025Updated last year
- Industrial Cybersecurity Conference Index☆13Mar 11, 2024Updated 2 years ago
- Predator is a directed fuzzing-based Web application vulnerability validation prototype. It automates verifying static vulnerability repo…☆14May 19, 2025Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆35Mar 19, 2026Updated 5 months ago
- ☆865Feb 13, 2026Updated 6 months ago
- A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evalua…☆4,618Updated this week
- Fenrir 是一个基于 MCP 协议与 AST 技术的代码审计工具,旨在解决安全研究与自动化代码审计领域中,面对大规模、结构复杂甚至反编译代码时,传统代码搜索与分析手段效率低、准确性差的问题。☆179Oct 21, 2025Updated 9 months ago
- Parsing-based Analyzer☆78Jun 8, 2025Updated last year
- A neurosymbolic framework for vulnerability detection in code☆413Jul 2, 2026Updated last month
- simpleIAST- 基于污点追踪的灰盒漏洞扫描工具。☆101Mar 24, 2026Updated 4 months ago