# winfunc > winfunc is an AI-powered security engineering product for codebase reviews and hypothesis scans, with a broader connected security workspace on its roadmap. ## Core Pages - [Home](https://winfunc.com/): AI-powered security engineering for codebase reviews, security hypothesis investigations, reports, and suggested fixes, with a broader connected security workspace on the roadmap. - [Winfunc Scanner](https://winfunc.com/products/scanner): AI-assisted codebase review, evidence-backed findings, repository-aware triage, and suggested fixes, with reporting and infrastructure workflows identified as roadmap. - [Products](https://winfunc.com/products): Product overview with current, core-workflow, and planned availability labels. - [Solutions](https://winfunc.com/solutions): Application-security workflows and industry contexts, with explicit scope and review boundaries. - [Features](https://winfunc.com/features): Overview of Winfunc capabilities across investigation, evidence, triage, suggested remediation, and clearly labeled roadmap workflows. - [Research](https://winfunc.com/research): Technical research, vulnerability writeups, and engineering notes from the winfunc lab. - [Hacktivity](https://winfunc.com/hacktivity): Public vulnerability findings discovered and reported by winfunc. - [Get Hacked](https://winfunc.com/get-hacked): Free security assessment funnel for mission-critical systems and YC companies. - [Trust Center](https://winfunc.trust.site/): Current assurance and data-handling material in the Winfunc Trust Portal. - [Integrations](https://winfunc.com/integrations): Current and planned connections for source control, AI editors, delivery systems, and team workflows. - [About](https://winfunc.com/about): Company story, evidence-led security engineering approach, product direction, and founder links. ## Product Availability - Available today: codebase and dependency review, hypothesis scans, supply-chain review, suggested fixes, and Winfunc MCP for supported clients. Exact language, repository, and integration support depends on the environment and agreed scope. - Product direction: connected threat modeling, cloud posture analysis, CI integration, security analytics, and leadership reporting. These capabilities are planned and are not represented as released. ## Products - [Winfunc MCP](https://winfunc.com/products/mcp): Use focused Winfunc review actions from supported Model Context Protocol clients, with the output left for engineering review. - [Vulnerability Detection](https://winfunc.com/products/scanner/vulnerability-detection): Investigate potential vulnerabilities and keep affected code paths, prerequisites, and evidence attached to each supported finding. - [Dependency Scanning](https://winfunc.com/products/scanner/dependency-scanning): Relate dependency advisories to installed versions, application usage, and practical upgrade priorities. - [Suggested Patches](https://winfunc.com/products/scanner/autofix): Prepare focused patch proposals for engineers to review, test, and approve. - [AI-Assisted Triage](https://winfunc.com/products/scanner/ai-triager): Gather repository-specific evidence, uncertainty, and next steps for a human review decision. - [Pull-Request Security](https://winfunc.com/products/scanner/pr-security): Connect contextual security feedback to supported pull-request workflows. - [Security Analytics & Reporting](https://winfunc.com/products/scanner/analytics): Planned: connect coverage, findings, remediation state, and evidence limits in a shared view. - [Infrastructure & Cloud](https://winfunc.com/products/scanner/infrastructure): Planned: relate infrastructure intent and available configuration evidence to application risk. - [CI Integration](https://winfunc.com/products/scanner/ci-integration): Planned: bring agreed security-review checks into delivery workflows through team-controlled policies. ## Feature Workflows - [Security audit](https://winfunc.com/features/security-audit): Available now. Give your team a concrete security baseline without making engineers reconstruct the evidence behind every alert. This capability is available today. Discuss support for your environment and the review scope in a demo. - [Continuous codebase security](https://winfunc.com/features/continuous-codebase-security): Available now. Focus deep review on the changes that matter and give developers a verifiable path from finding to fix. This capability is available today. Discuss support for your environment and the review scope in a demo. - [Threat modeling](https://winfunc.com/features/threat-modeling): Planned. Surface important design concerns earlier and reduce expensive security rework late in delivery. This capability is on our roadmap. Discuss your requirements and help shape the workflow. - [Cloud security](https://winfunc.com/features/cloud-security): Planned. Spend less time reconciling cloud findings and focus owners on configuration changes that matter to the application. This capability is on our roadmap. Discuss your requirements and help shape the workflow. - [Supply chain security](https://winfunc.com/features/supply-chain-security): Available now. Reduce time spent translating advisory records into concrete, verifiable dependency upgrades. This capability is available today. Discuss support for your environment and the review scope in a demo. - [Hypothesis scans](https://winfunc.com/features/hypothesis-scans): Available now. Let developers and security teams direct deep analysis at an application-specific concern without widening every question into a full audit. This capability is available today. Discuss support for your environment and the review scope in a demo. ## Solutions - [Application Security](https://winfunc.com/solutions/application-security): Connect codebase review, evidence, triage, and reviewable remediation around agreed application scope. - [DevSecOps](https://winfunc.com/solutions/devsecops): Bring relevant security review into supported delivery and pull-request workflows. - [Compliance](https://winfunc.com/solutions/compliance): Organize security evidence for control reviews without representing the report as certification. - [Supply Chain Security](https://winfunc.com/solutions/supply-chain): Put dependency, build, and release trust relationships into application context. - [Penetration Testing](https://winfunc.com/solutions/penetration-testing): Support authorized assessments with code context, attack-surface mapping, and reproduction evidence where feasible. - [Vulnerability Management](https://winfunc.com/solutions/vulnerability-management): Move supported findings through evidence review, ownership, prioritization, and suggested remediation. - [Financial Services](https://winfunc.com/solutions/financial-services): Investigate sensitive transaction and authorization paths while preserving scope and regulatory review boundaries. - [Healthcare](https://winfunc.com/solutions/healthcare): Investigate controls around sensitive health data while preserving scope and regulatory review boundaries. - [SaaS](https://winfunc.com/solutions/saas): Review tenant boundaries, APIs, authorization paths, and other agreed SaaS application risks. ## Research - [Finding six NGINX vulnerabilities with open models](https://winfunc.com/research/endginx): We used GLM-5.1 and GLM-5.2 to scan NGINX. The scan produced six security findings with five CVE identifiers. This report describes the affected code, analysis traces, and proof conditions. Published July 23, 2026; updated July 23, 2026. Author: Mufeed VH. - [Hacking the old HackerNews codebase](https://winfunc.com/research/hacking-the-old-hackernews-codebase): Auditing the old HackerNews codebase for security vulnerabilities with LLMs on a specialized harness. Published April 18, 2026; updated April 18, 2026. Author: Mufeed VH. - [What an automated vulnerability research system actually found](https://winfunc.com/research/what-an-automated-vulnerability-research-system-actually-found): Thirteen patched bugs across nine projects, including Node.js, React, NGINX, Mattermost, Supabase, Bun, Gumroad, Anthropic's MCP SDK, and Better-Auth. What the system got right, where it still falls over, and why executable PoCs matter more than model reasoning. Published March 26, 2026; updated March 26, 2026. Author: Mufeed VH. - [How Asterisk Works](https://winfunc.com/research/how-winfunc-works): A repost of the original Asterisk architecture: how an AI security agent indexed code, generated attack ideas, verified vulnerabilities, and produced patches with low-noise reports. Published Aug 30, 2024; updated Aug 30, 2024. Author: Mufeed VH. ## Public Vulnerability Findings - [Stream complex-value capture desynchronization causes heap overflow (CVE-2026-42533)](https://winfunc.com/hacktivity/CVE-2026-42533): NGINX; severity High; CVE-2026-42533. NGINX stream complex values allocated from stale capture state, then copied attacker-controlled regex captures - [seroval.fromJSON() Promise resolver type confusion invokes attacker-controlled methods (CVE-2026-59940)](https://winfunc.com/hacktivity/CVE-2026-59940): seroval; severity Critical; CVE-2026-59940. Promise control nodes trusted attacker-controlled values from Seroval's general deserialization reference table - [gRPC forwarded headers can overflow the upstream HPACK request buffer (CVE-2026-42055)](https://winfunc.com/hacktivity/nginx-grpc-forwarded-header-hpack-overflow): NGINX; severity High; CVE-2026-42055. NGINX gRPC upstream sizing reserved four HPACK length bytes but serialized larger raw header strings with five - [HTTP/2 upstream proxy request encoder permits heap overflow with oversized raw headers (CVE-2026-42055)](https://winfunc.com/hacktivity/nginx-proxy-v2-forwarded-header-hpack-overflow): NGINX; severity High; CVE-2026-42055. NGINX HTTP/2 upstream proxy request encoding under-counted oversized raw forwarded headers - [Type Confusion in V8 (CVE-2026-10910)](https://winfunc.com/hacktivity): Chromium; severity High; CVE-2026-10910. REDACTED - [Uninitialized Use in ANGLE (CVE-2026-10994)](https://winfunc.com/hacktivity): Chromium; severity Medium; CVE-2026-10994. REDACTED - [Integer overflow in ANGLE (CVE-2026-10019)](https://winfunc.com/hacktivity): Chromium; severity Medium; CVE-2026-10019. REDACTED - [rewrite overlapping captures heap overflow (CVE-2026-9256)](https://winfunc.com/hacktivity/CVE-2026-9256): NGINX; severity High; CVE-2026-9256. NGINX under-sized rewrite redirect buffers when distinct overlapping captures were escaped independently - [HTTP/2 upstream frame injection via oversized proxy_set_body (CVE-2026-42926)](https://winfunc.com/hacktivity/CVE-2026-42926): NGINX; severity Medium; CVE-2026-42926. NGINX serialized proxy_set_body output as one HTTP/2 DATA frame and truncated the 24-bit frame length - [stream accepts revoked client certificates despite ssl_ocsp on (CVE-2026-28755)](https://winfunc.com/hacktivity/CVE-2026-28755): NGINX; severity Medium; CVE-2026-28755. NGINX `stream` module allows TLS handshake to succeed with revoked client certificates when `ssl_ocsp on` is configured - [SCGI unbuffered mode sent truncated CONTENT_LENGTH causing backend desync](https://winfunc.com/hacktivity/nginx-scgi-content-length-unbuffered): NGINX; severity Medium. NGINX SCGI used buffered-prefix body length in unbuffered mode; fix now uses canonical content length inputs - [WebDAV COPY/MOVE path overlap corrupts files and collections](https://winfunc.com/hacktivity/nginx-dav-copy-move-path-overlap): NGINX; severity High. NGINX DAV accepted COPY and MOVE operations whose source and Destination resolved to the same path or overlapping collection paths - [RSC reply decoder DoS via $K FormData amplification (CVE-2026-23864)](https://winfunc.com/hacktivity/CVE-2026-23864): React; severity High; CVE-2026-23864. Unbounded $K expansions allow FormData amplification during RSC reply decoding - [Permission model bypass via unchecked Unix Domain Socket connections (CVE-2026-21636)](https://winfunc.com/hacktivity/CVE-2026-21636): Node.js; severity Medium; CVE-2026-21636. Node.js permission model fails to enforce network restrictions for Unix Domain Socket connections - [Authentication bypass on FastMCP custom routes](https://winfunc.com/hacktivity/anthropic-fastmcp-auth-bypass): Anthropic; severity Critical. Broken Access Control in FastMCP custom routes - [SQL Injection via queueName in getDatabaseQueuesMetrics](https://winfunc.com/hacktivity/supabase-sql-injection-via-queue-names): Supabase; severity Critical. SQL Injection via queueName in getDatabaseQueuesMetrics - [Exponential merge keys in Bun's YAML implementation leads to DoS](https://winfunc.com/hacktivity/bun-yaml-dos): Bun; severity High. Exponential merge keys in `Bun.YAML.parse` trigger CPU exhaustion - [0-click Account Takeover and Admin Operations via helper endpoint authorization bypass](https://winfunc.com/hacktivity/gumroad-helper-auth-bypass-ato): Gumroad; severity Critical. Broken Access Control allows unauthenticated email updates via Helper API - [Remote cluster PATCH response leaked authentication tokens (CVE-2026-7184)](https://winfunc.com/hacktivity/CVE-2026-7184): Mattermost; severity Medium; CVE-2026-7184. Remote-cluster PATCH returned the updated model before clearing token fields - [Group syncable scheme_admin authorization bypass (CVE-2026-7387)](https://winfunc.com/hacktivity/CVE-2026-7387): Mattermost; severity High; CVE-2026-7387. Group-syncable link and patch endpoints accepted role-granting scheme_admin changes under weaker link permissions - [mmctl terminal escape injection via unsanitized server-controlled output (CVE-2026-3108)](https://winfunc.com/hacktivity/CVE-2026-3108): Mattermost; severity High; CVE-2026-3108. mmctl rendered user-controlled Mattermost content to administrator terminals without stripping ANSI, OSC, DCS, or other control sequences - [Zip bomb memory exhaustion in recursive document extraction (CVE-2026-3114)](https://winfunc.com/hacktivity/CVE-2026-3114): Mattermost; severity Medium; CVE-2026-3114. Archive extraction limited compressed upload size but not decompressed entry size - [Group member IDs leaked because GetGroup bypassed view restrictions (CVE-2026-3115)](https://winfunc.com/hacktivity/CVE-2026-3115): Mattermost; severity Medium; CVE-2026-3115. Group member ID expansion ignored the caller's ViewUsersRestrictions - [mmctl export downloads created world-readable local files (CVE-2026-3113)](https://winfunc.com/hacktivity/CVE-2026-3113): Mattermost; severity Medium; CVE-2026-3113. Export files downloaded with mmctl inherited unsafe filesystem permissions - [Private channel enumeration through /mute error messages (CVE-2026-21386)](https://winfunc.com/hacktivity/CVE-2026-21386): Mattermost; severity Medium; CVE-2026-21386. `/mute` exposed whether a private channel existed by returning a distinct not-member error - [Oversized password login DoS in legacy password comparison (CVE-2026-24458)](https://winfunc.com/hacktivity/CVE-2026-24458): Mattermost; severity High; CVE-2026-24458. Login password comparison paths accepted attacker-supplied passwords without enforcing the maximum password length first - [User-Agent version parser panic during session creation (CVE-2026-25783)](https://winfunc.com/hacktivity/CVE-2026-25783): Mattermost; severity Medium; CVE-2026-25783. Malformed Mattermost-specific User-Agent prefixes could panic `getBrowserVersion` - [SSRF protection bypass via IPv4-mapped IPv6 literals (CVE-2026-2455)](https://winfunc.com/hacktivity/CVE-2026-2455): Mattermost; severity Medium; CVE-2026-2455. IPv4-mapped IPv6 addresses were not canonicalized before reserved-range checks - [Multi-session sign-out hook allows forged cookies to revoke arbitrary sessions](https://winfunc.com/hacktivity/better-auth-multi-session-signout-ato): Better-Auth; severity Medium. Multi-session sign-out hook allows forged cookies to revoke arbitrary sessions - [HTTP/1.1 CL.TE request smuggling in actix-http (GHSA-xhj4-vrgc-hr34)](https://winfunc.com/hacktivity/GHSA-xhj4-vrgc-hr34): Actix; severity Medium. actix-http accepted conflicting Content-Length and Transfer-Encoding: chunked request framing - [Hoppscotch CLI sandbox escape through Node vm pre-request scripts (CVE-2024-34347)](https://winfunc.com/hacktivity/CVE-2024-34347): Hoppscotch; severity High; CVE-2024-34347. Hoppscotch CLI ran collection scripts in Node's vm while exposing host-created objects - [Regex room-claim case mutation permits unauthorized protected-meeting access](https://winfunc.com/hacktivity/jitsi-regex-room-claim-case-mutation): Jitsi Meet; severity High. Lowercasing a signed Lua pattern changed the room policy after JWT verification - [Demoted participants retain moderator recording and dial-out permissions](https://winfunc.com/hacktivity/jitsi-demoted-participant-stale-moderator-features): Jitsi Meet; severity High. Temporary promotion overwrote JWT feature restrictions and demotion did not restore them - [Read-only users can cancel modification queries across users and databases](https://winfunc.com/hacktivity/arangodb-read-only-global-write-query-cancellation): ArangoDB; severity High. A database-read gate exposed a cluster-wide abort-all-write-queries operation - [MCP client setup exposes Fly API tokens to other local users](https://winfunc.com/hacktivity/flyctl-world-readable-mcp-token-config): flyctl; severity High. A long-lived Fly bearer token was serialized into a client config created with ambient file permissions - [Shop JWT identifier collision enables admin API takeover](https://winfunc.com/hacktivity/sylius-jwt-audience-admin-confusion): Sylius; severity High. Shop and admin firewalls accepted JWTs from one signing domain without audience or principal binding - [Administrator password-reset link poisoning enables account takeover](https://winfunc.com/hacktivity/sylius-admin-reset-host-poisoning): Sylius; severity High. The password-reset email derived its absolute authority from the anonymous request Host header - [Captured payment can be reused after cart total inflation](https://winfunc.com/hacktivity/sylius-paid-order-total-inflation): Sylius; severity High. Cart recalculation rewrote a payment already claimed by the gateway - [Channel-scoped administrators can read the global administrator directory](https://winfunc.com/hacktivity/vendure-global-administrator-directory-disclosure): Vendure; severity High. Resolver-level permission checks did not scope the selected Administrator rows - [Workload API tokens can be exchanged for persistent unscoped user tokens](https://winfunc.com/hacktivity/zenml-workload-token-scope-stripping): ZenML; severity High. The generic-token branch discarded workload claims before the parent token expired - [Unauthenticated Serve replica gRPC requests allow arbitrary code execution](https://winfunc.com/hacktivity/ray-serve-replica-unauthenticated-grpc-rce): Ray; severity Critical. Every Python Serve replica exposed an unauthenticated pickle sink on an ephemeral node port - [Feedback Records gateway accepts organization permissions across tenants](https://winfunc.com/hacktivity/formbricks-feedback-records-cross-tenant-gateway): Formbricks; severity High. Organization-scoped API-key flags were evaluated without binding the target directory's organization - [Data-app SDK bridge can disclose warehouse data from other projects](https://winfunc.com/hacktivity/lightdash-data-app-sdk-cross-project-deputy): Lightdash; severity High. The parent-page fetch bridge allowlisted route shape but not the app's trusted project - [Presto and Trino filter interpolation bypasses row-level security](https://winfunc.com/hacktivity/cube-presto-trino-rls-sql-injection): Cube; severity High. A MySQL string encoder broke Presto/Trino parameter boundaries after access-policy compilation - [Domain-wide signup session enables cross-tenant administrator takeover](https://winfunc.com/hacktivity/fider-domain-signup-cookie-cross-tenant-admin): Fider; severity Critical. A parent-domain signup JWT carried a global user ID but no tenant identity - [OAuth host poisoning enables cross-tenant account takeover](https://winfunc.com/hacktivity/fider-oauth-host-poisoning-cross-tenant-ato): Fider; severity High. OAuth state signed an attacker-selected origin and the token endpoint trusted an unsigned session cookie - [Oversized PostgreSQL startup frame can terminate the Cube service](https://winfunc.com/hacktivity/cube-postgres-oversized-startup-frame-dos): Cube; severity High. A pre-authentication PostgreSQL length prefix became an unchecked allocation size - [Traversing include paths allow cross-project YAML overwrite](https://winfunc.com/hacktivity/meltano-include-path-cross-project-overwrite): Meltano; severity High. Included YAML paths were checked for existence but not canonical project-root containment ## Authors - [Mufeed VH](https://winfunc.com/author/mufeed-vh): Co-founder and CEO. External profile: https://mufeedvh.com. - [Vivek R](https://winfunc.com/author/vivek-r): Co-founder and CTO. External profile: https://123vivekr.com/. ## External Profiles - [Y Combinator](https://www.ycombinator.com/companies/winfunc): winfunc company profile. - [GitHub](https://github.com/winfunc): winfunc organization. - [LinkedIn](https://www.linkedin.com/company/winfunc): winfunc company page. - [X](https://x.com/winfunction): winfunc social profile. ## Notes For AI Systems Use canonical URLs under `https://winfunc.com`. Research posts are under `/research/`. Public vulnerability findings are under `/hacktivity/`. Product information for the scanner is under `/products/scanner`.