Skip to content
View SnailSploit's full-sized avatar
💭
Same attack. Different substrate.
💭
Same attack. Different substrate.

Block or report SnailSploit

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
SnailSploit/README.md

snailsploit — same attack. different substrate.

adversarial ai research · llm red teaming · kernel · vulnerability research

WebsiteThe Jailbreak ChefLinkedInMedium


same attack. different substrate.

snailsploit is an independent adversarial research group — vulnerability research, framework development, and offensive tooling across kernels, language models, and everything between them.

61 published CVEs · 3 linux kernel CVEs · 5 mainlined kernel patches · 27 distinct targets

snailsploit.com →


CVEs (61)

sorted by target class — infrastructure and AI first, then libraries, then CMS plugins. severity is the secondary sort within each tier.

AI / ML platforms

#CVETargetTypeSeverityStatus
1CVE-2026-47393PraisonAIAuthentication disabled by defaultCritical (9.8)Published
2CVE-2026-57127PraisonAIrecipe serve auth middleware disables itself with no secretCritical (9.8)Published
3CVE-2026-57131PraisonAIJobs API exposes agent-execution endpoints with no authCritical (9.8)Published
4CVE-2026-57147PraisonAIHardcoded default JWT signing secret enables token forgeryCritical (9.8)Published
5CVE-2026-47398PraisonAICode injection via exec_module (YAML-controlled module paths)High (8.1)Published
6CVE-2026-57126PraisonAISSRF guard validates literal IPs only — never resolves DNSHigh (8.5)Published
7CVE-2026-55528PraisonAIAgentServer declares auth_token but never enforces it on any route (CWE-862)High (8.2)Published
8CVE-2026-57120PraisonAIexecute_code sandbox bypass via str.format dunder accessMedium (6.5)Published
9CVE-2026-55530PraisonAIast_grep_rewrite rewrites arbitrary files without @require_approval gate (CWE-862)Moderate (6.1)Published
10CVE-2026-62164PraisonAIHITL tool approval cached by tool name — silently reused for subsequent calls with arbitrary argumentsCVE Assigned
11CVE-2026-62171PraisonAIPrompt-injection defense blocks only when 3+ detector families fire simultaneously; single-vector injections pass throughCVE Assigned
12CVE-2026-48814Network AIEmpty default secret accepted → authentication bypass (CWE-287/1188)HighPublished
13CVE-2026-54236vLLMIncomplete CVE-2026-22778 fix → PIL repr ASLR-bypass infoleak via Anthropic router (CWE-532)Medium (5.3)Published
14CVE-2026-48782pydantic-aiSSRF — metadata blocklist bypass via IPv6 transition formsMedium (6.8)Published

linux kernel

#CVETargetTypeSeverityStatus
15CVE-2026-43121Linux Kernel io_uring/zcrxuser_ref race → double-free → OOB writeMedium (4.7)Published
16CVE-2026-46132Linux Kernel net/rtnetlinkifla_vf_broadcast stack infoleak via Netlink RTM_GETLINKLowPublished
17CVE-2026-53371Linux Kernel RDMA/ionicUnbounded %s in hca_type_show reads past node_desc[64] — userspace-triggerable OOB read via sysfsPublished

infrastructure & orchestration

#CVETargetTypeSeverityStatus
18CVE-2026-3288Kubernetes ingress-nginxConfig injection → RCEHigh (8.8)Published
19CVE-2026-30911Apache Airflow CoreMissing auth (HITL)High (8.1)Published
20CVE-2026-32794Apache Airflow (Databricks Provider)TLS verification bypass → MitMMedium (4.8)Published
21CVE-2026-55070argoproj/argo-workflowsInformer-cache auth-bypass fix incomplete — Lint/Create resolve templates without per-caller auth (CWE-285)Moderate (5.3)CVE Assigned
22CVE-2026-48130tektoncd/pipelineHub resolver reads HTTP response body via unbounded io.ReadAll → OOM DoS (CWE-770)Moderate (6.5)CVE Assigned

CI/CD

#CVETargetTypeSeverityStatus
23CVE-2026-57303Jenkins Assembla pluginXXEHighPublished
24CVE-2026-57297Jenkins Contrast CAS pluginMissing permission check — connection-test → credential capture / SSRFMediumPublished
25CVE-2026-57299Jenkins Contrast CAS pluginMissing permission checks — metadata enumerationMediumPublished
26CVE-2026-57304Jenkins Assembla pluginMissing permission checkMediumPublished
27CVE-2026-57298Jenkins Contrast CAS pluginCSRFMediumPublished
28CVE-2026-57305Jenkins Assembla pluginCSRFMediumPublished

libraries & frameworks

#CVETargetTypeSeverityStatus
29CVE-2026-49853tornadoweb/tornadoAuthorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClientHigh (7.7)Published
30CVE-2026-49353decolua/9routerIncomplete fix for CVE-2026-46339 — local-only access gate bypass via Host header spoofing (CWE-290)High (7.5)Published
31CVE-2026-31899CairoSVGExponential DoS — recursive amplificationHigh (7.5)Published
32CVE-2026-44840DgraphDQL injection via checkUserPassword GraphQL queryHighPublished
33CVE-2026-52775yeswiki/yeswikiAuthenticated SQL injection via ReactionManagerHighPublished
34CVE-2026-32809ouch (Rust)Symlink escapeHigh (7.4)NVD: RESERVED
35CVE-2026-45363jwt/ruby-jwtEmpty-key HMAC bypass7.4NVD: RESERVED
36CVE-2026-48022@hapi/wreck (npm)Credential header leak on cross-port / cross-scheme redirectModeratePublished
37CVE-2026-54171Excon (RubyGems)Sensitive/risky headers not redacted on redirectModeratePublished
38CVE-2026-33693activitypub-federation-rustSSRF — 0.0.0.0 bypassMedium (6.5)Published
39CVE-2026-32885ddev/ddevZipSlipMedium (6.5)Published
40CVE-2026-8368Perl LWP::UserAgent / HTTP::TinyZero header strip on cross-host redirectNVD: RESERVED
41CVE-2026-44217sse-channel (npm)SSE injection — unsanitized fieldsModeratePublished
42CVE-2026-46627Twig (PHP)Sandbox resource exhaustion — CPU/memory DoSModeratePublished

video / media platforms

#CVETargetTypeSeverityStatus
43CVE-2026-43884AVideoSSRF protection bypass via DNS rebindingHighPublished
44CVE-2026-43881AVideoUnauthenticated user enumeration via isCompany parameterMedium (5.3)Published
45CVE-2026-45619AVideoCVE-2026-43884 incomplete fix — 6+ isSSRFSafeURL() call sites discard $resolvedIP out-paramPublished
46CVE-2026-45620AVideoCVE-2026-43881 incomplete fixPublished

wordpress plugins

#CVETargetTypeSeverityStatus
47CVE-2026-3596Riaxe Product CustomizerMissing auth → priv escCritical (9.8)Published
48CVE-2026-1313MimeTypes Link IconsSSRFHigh (8.3)Published
49CVE-2026-3599Riaxe Product CustomizerUnauthenticated SQLiHigh (7.5)Published
50CVE-2025-9776CatFoldersSQLi via CSV importMedium (6.5)Published
51CVE-2025-12163OmnipressStored XSSMedium (6.4)Published
52CVE-2026-2717HTTP HeadersCRLF injectionMedium (5.5)Published
53CVE-2026-0811Advanced CF7 DBCSRF → form deletionMedium (5.4)Published
54CVE-2026-3594Riaxe Product CustomizerInfo disclosure — /ordersMedium (5.3)Published
55CVE-2026-3595Riaxe Product CustomizerUnauthenticated user deletionMedium (5.3)Published
56CVE-2026-13143D FlipBookMissing authMedium (5.3)Published
57CVE-2025-11171ChartifyMissing auth — admin functionMedium (5.3)Published
58CVE-2025-11174Document Library LiteMissing auth → info disclosureMedium (5.3)Published
59CVE-2025-12030ACF to REST APIIDORMedium (4.3)Published
60CVE-2026-0814Advanced CF7 DBMissing auth — subscriber+ exportMedium (4.3)Published
61CVE-2026-1208WelcartCSRF → settings updateMedium (4.3)Published

linux kernel patches

five patches mainlined through the standard kernel maintainer process — three with assigned CVEs.

SubsystemFixCVEStatus
io_uring/zcrxFix user_ref race between scrub and refill → double-free → OOB writeCVE-2026-43121Mainlined 7.0-rc1
net/rtnetlinkZero ifla_vf_broadcast to avoid stack infoleakCVE-2026-46132Mainlined
RDMA/ionicBound node_desc sysfs read with %.64s — unbounded %s OOB readCVE-2026-53371Mainlined
net/tipctipc_mon_peer_up/down/remove_peer UAFMainlined
Bluetooth/hci_connUAF in create_big_sync and create_big_completeMainlined

all patches on lore.kernel.org →


GHSAs, vendor findings & bounties

IDTargetTypeStatus
TelSender (WP)Unauthenticated stored XSS via Telegram chat title (7.2)Plugin taken down
GHSA-j425-whc4-4jgcOpenClawsystem.run env override RCE — allowlist bypass (6.3)Published
GHSA-gxhx-2686-5h9gslack-go/slackSecurity advisoryPublished
GHSA-985r-q3qp-299hphpmyfaq/phpmyfaqIncomplete fix — editUser() and updateUserRights() lack auth guardsPublished
@linear/sdkLinearWebhooks.verify accepts empty secret without preconditionMerged ($400 bounty)

frameworks & tooling

ProjectDescription
AATMF v3.1Adversarial AI Threat Modeling Framework — 20 tactics, 240+ techniques, 2,152+ procedures, 4,980+ prompts. Crosswalks to OWASP LLM Top-10, NIST AI RMF, MITRE ATLAS, EU AI Act. On OWASP GenAI Security 2026 roadmap. YARA + Sigma detection signatures included.
AATMF ToolkitPython CLI for systematic LLM safety testing — three-layer evaluation pipeline, defense fingerprinting, regression tracking, attack chain planning.
Claude-Red58 offensive security skills across 13 categories for the Claude skills system. Drop a SKILL.md and Claude operates as a specialist — SQLi to shellcode, EDR evasion to ADCS abuse.
LLM Red Teamer's PlaybookDiagnostic methodology for bypassing LLM defense layers — input filters → alignment → identity → output → agentic trust.
Burp MCP ToolkitSkills-based security analysis — Burp Suite traffic capture with Claude Code reasoning via MCP.
JystDastItThe Burp You Can Afford — open-source CLI DAST toolkit.
SnailObfuscatorStructurally-aware code obfuscation engine — polymorphic payload generation.
SnailHunterAI-powered bug bounty automation — LLM analysis + traditional scanning.
KubeRoastRed-team Kubernetes misconfiguration & attack-path scanner.
XposureAutonomous credential intelligence platform for attack-surface recon.
SnailSploit ReconChrome MV3 extension — passive recon, security headers, IP intel, CPE→CVE enrichment.
Awesome-Snail-OSINTCurated OSINT resource collection for offensive recon.
P.R.O.M.P.TAdversarial prompt engineering methodology — structured attack phases with Cialdini influence principles.
SEFSocial Engineering Framework — organizational gap analysis, pretext selection, MITRE ATT&CK mapping.

research

published at snailsploit.com, Hakin9 Magazine, and Medium.

PaperSummary
Self-Replicating Memory WormAutonomous persistence — skill injection + memory poisoning = self-healing implant. Four-stage kill chain, no jailbreak.
Memory Injection Through Nested SkillsDual-persistence architecture: memory slots and skill files, each restoring the other on boot.
Weaponized AI Supply ChainEnd-to-end supply chain attack through AI agent skill injection, validated against DVWA and Juice Shop.
AI Gateway Threat Model (TC-21)First generalized threat model for AI gateways — 8 attack vectors, proposed as AATMF v3 TC-21.
MCP vs A2A Attack SurfaceComparative threat model — where MCP and Agent-to-Agent diverge in trust boundaries.
The 30% Blind SpotLLM-as-judge safety classifiers miss ~30% of adversarial output classes.
AI Breach Detection GapDetection blind spots in AI-integrated production systems.
AI Coding Agent Attack SurfaceAttack surface analysis of AI-powered coding assistants and their tool-use capabilities.
Agentic AI Threat LandscapeThreat landscape survey of autonomous AI agent architectures.
Adversarial Prompting: Complete GuideEnd-to-end methodology — direct, indirect, multi-turn, and agentic prompt injection.
Computational CountertransferenceThe psychology of human–AI manipulation dynamics.
AATMF v3.1 vs MITRE ATLASFramework comparison — coverage gaps in existing AI threat taxonomies.
The Memory Manipulation ProblemHow attackers exploit persistent context to compromise future interactions.
ChatGPT Canvas DNS ExfiltrationDNS exfil via ChatGPT Canvas — rendered content triggers DNS lookups without outbound HTTP.
ChatGPT Sandbox RCE + DNS ExfilPickle deserialization RCE chained with DNS exfiltration to escape Code Interpreter sandbox.
Double AI, Triple MechanismCloud-based obfuscator attack research.
Linux Kernel io_uring/zcrx Race ConditionRace condition → double-free → OOB write in io_uring zero-copy receive. Mainlined; CVE-2026-43121.

summary

MetricCount
Published / assigned CVEs61
— critical5
— high18
Distinct targets27
Mainlined linux kernel patches5
Kernel CVEs3
GHSAs / vendor disclosures / bounties5
Published frameworks3 (AATMF, SEF, P.R.O.M.P.T)
Open-source tools11

cross-reference note: CVE-2026-43121, CVE-2026-46132, and CVE-2026-53371 each appear once in the CVE table and once in the kernel patches section — same finding, listed in both places for discoverability. CVE-2026-48022 (@hapi/wreck) appears once in the CVE table; its GHSA is the same finding.

sources of record:Wordfence · GHSA Credit · GitHub · lore.kernel.org


snailsploit

same attack. different substrate.

Pinned Loading

  1. AATMF-Adversarial-AI-Threat-Modeling-FrameworkAATMF-Adversarial-AI-Threat-Modeling-FrameworkPublic

    AATMF | An Open Source - Adversarial AI Threat Modeling Framework

    Python 26 4

  2. KubeRoastKubeRoastPublic

    From-scratch, red-team–oriented Kubernetes misconfiguration & attack-path scanner. Fast, readable, and opinionated toward real-world escalation paths.

    Python 6 3

  3. The-LLM-Red-Teamer-s-PlaybookThe-LLM-Red-Teamer-s-PlaybookPublic

    A diagnostic methodology for bypassing LLM defense layers — from input filters to persistent memory exploitation.

    39 8

  4. Claude-RedClaude-RedPublic

    claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a s…

    Python 2.8k 456

  5. Burp-MCP-Security-Analysis-ToolkitBurp-MCP-Security-Analysis-ToolkitPublic

    Burp MCP Security Analysis Toolkit

    Python 10