Find the bug the code forgot.
Source-to-sink vulnerability research.
Sandbox escape → host RCE
vm2 · NodeVM denylist
Three steps. One report.
Point it at a repo
$ vulnfinder owner/repoIt traces source to sink
Eight disciplined phases in one warm session.
You get a report.md
Structured findings. Public-only. Medium severity and up.
Eleven shapes that convert.
Twenty-one accepted bugs.
Public records, sorted by impact.
Every disclosure sharpens the method.
You disclose
Report the outcome — or we auto-detect it from public GitHub advisories that credit you.
We learn
What converts, and what maintainers reject — distilled into new archetype and rejection rules.
Everyone gains
The next release hunts smarter. Same tool, sharper edge.
Opt-in, always. We only ever see a finding's shape — class, archetype, CVSS — never your repository or the finding itself.
Sign in with GitHubEarned, not claimed.
Outcomes are auto-verified from public advisories that credit your handle. No self-reporting.
Sign in with GitHub to claim your verified findings — launching soon.
Start finding bugs.
One command. No API key, no account.
by Sneh Bavarva