Every security team knows the pattern: you want a proper assessment of an app, but the options are waiting weeks for a consultancy slot, or stitching together a dozen tools and babysitting them for days. Bug bounty hunters know a variant of the same problem — the toolchain is powerful but fragmented, and every judgement call is on you.
We are building a third option. BugTraceAI is an open-source, self-hosted framework for authorized bug bounty and penetration testing. It runs an autonomous agentic pipeline: AI agents plan and prioritize the work, specialist tools and browser validation collect the evidence, and every finding comes out with something you can verify before you file it.
Plenty of scanners already automate checks. The gap BugTraceAI aims at is the layer above: deciding what to test, in what order, and what to do with ambiguous signals.
In BugTraceAI, agents drive a six-phase pipeline:
The AI reasons and prioritizes; deterministic security tools (including Go fuzzers and browser-based validation via Playwright) adjudicate. The design principle in one line: AI output is a hypothesis — evidence makes it a finding.
Plus BugStore — a deliberately vulnerable practice shop with 32 planted OWASP vulnerabilities, so you can try the whole workflow legally.
Everything is self-hosted and Apache-2.0 licensed. Scans, reports and evidence stay on your infrastructure, and analysis runs with your own LLM provider key.
Three CVEs disclosed so far, found with BugTraceAI:
| Product | CVE | CVSS |
|---|---|---|
| Wallos | CVE-2026-27479 | 7.7 High |
| ZoneMinder | CVE-2026-27470 | 8.8 High |
| Piwigo | CVE-2026-27834 | 7.2 High | The project was presented on stage at DEF CON 34 (Las Vegas), RootedCON 2026 (Madrid) and HKOSCon 2026 (Hong Kong). Component versions are currently in beta — treat outputs as leads to verify, not verdicts. (That is the point of the evidence-first design.)
BugTraceAI is built for authorized security testing only. Only test applications you have explicit written permission to test.