cd /news/ai-agents/meet-bugtraceai-an-open-source-self-… · home › topics › ai-agents › article
[ARTICLE · art-146516] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Meet BugTraceAI: an open-source, self-hosted agentic pentester

A developer has released BugTraceAI, an open-source, self-hosted agentic penetration-testing framework that runs a six-phase pipeline in which AI agents plan and prioritize testing while deterministic tools such as Go fuzzers and Playwright browser validation collect verifiable evidence. The project, licensed under Apache-2.0 and presented at DEF CON 34, RootedCON 2026 and HKOSCon 2026, has so far led to three disclosed CVEs in Wallos, ZoneMinder and Piwigo, and ships with BugStore, a deliberately vulnerable practice shop containing 32 planted OWASP vulnerabilities.

by read2 min views1 publishedOct 7, 2026

Every security team knows the pattern: you want a proper assessment of an app, but the options are waiting weeks for a consultancy slot, or stitching together a dozen tools and babysitting them for days. Bug bounty hunters know a variant of the same problem — the toolchain is powerful but fragmented, and every judgement call is on you.

We are building a third option. BugTraceAI is an open-source, self-hosted framework for authorized bug bounty and penetration testing. It runs an autonomous agentic pipeline: AI agents plan and prioritize the work, specialist tools and browser validation collect the evidence, and every finding comes out with something you can verify before you file it.

Plenty of scanners already automate checks. The gap BugTraceAI aims at is the layer above: deciding what to test, in what order, and what to do with ambiguous signals.

In BugTraceAI, agents drive a six-phase pipeline:

The AI reasons and prioritizes; deterministic security tools (including Go fuzzers and browser-based validation via Playwright) adjudicate. The design principle in one line: AI output is a hypothesis — evidence makes it a finding.

Plus BugStore — a deliberately vulnerable practice shop with 32 planted OWASP vulnerabilities, so you can try the whole workflow legally.

Everything is self-hosted and Apache-2.0 licensed. Scans, reports and evidence stay on your infrastructure, and analysis runs with your own LLM provider key.

Three CVEs disclosed so far, found with BugTraceAI:

| Product | CVE | CVSS |

|---|---|---|
| Wallos | CVE-2026-27479 | 7.7 High | 

| ZoneMinder | CVE-2026-27470 | 8.8 High |

| Piwigo | CVE-2026-27834 | 7.2 High | The project was presented on stage at DEF CON 34 (Las Vegas), RootedCON 2026 (Madrid) and HKOSCon 2026 (Hong Kong). Component versions are currently in beta — treat outputs as leads to verify, not verdicts. (That is the point of the evidence-first design.)

BugTraceAI is built for authorized security testing only. Only test applications you have explicit written permission to test.

── more in #ai-agents 4 stories · sorted by recency
── more on @bugtraceai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/meet-bugtraceai-an-o…] indexed:0 read:2min 2026-10-07 · —