{"slug": "meet-bugtraceai-an-open-source-self-hosted-agentic-pentester", "title": "Meet BugTraceAI: an open-source, self-hosted agentic pentester", "summary": "A developer has released BugTraceAI, an open-source, self-hosted agentic penetration-testing framework that runs a six-phase pipeline in which AI agents plan and prioritize testing while deterministic tools such as Go fuzzers and Playwright browser validation collect verifiable evidence. The project, licensed under Apache-2.0 and presented at DEF CON 34, RootedCON 2026 and HKOSCon 2026, has so far led to three disclosed CVEs in Wallos, ZoneMinder and Piwigo, and ships with BugStore, a deliberately vulnerable practice shop containing 32 planted OWASP vulnerabilities.", "body_md": "Every security team knows the pattern: you want a proper assessment of an app, but the options are waiting weeks for a consultancy slot, or stitching together a dozen tools and babysitting them for days. Bug bounty hunters know a variant of the same problem — the toolchain is powerful but fragmented, and every judgement call is on you.\n\nWe are building a third option. **BugTraceAI** is an open-source, self-hosted framework for authorized bug bounty and penetration testing. It runs an autonomous agentic pipeline: AI agents plan and prioritize the work, specialist tools and browser validation collect the evidence, and every finding comes out with something you can verify before you file it.\n\nPlenty of scanners already automate checks. The gap BugTraceAI aims at is the layer above: deciding what to test, in what order, and what to do with ambiguous signals.\n\nIn BugTraceAI, agents drive a six-phase pipeline:\n\nThe AI reasons and prioritizes; deterministic security tools (including Go fuzzers and browser-based validation via Playwright) adjudicate. The design principle in one line: **AI output is a hypothesis — evidence makes it a finding.**\n\nPlus **BugStore** — a deliberately vulnerable practice shop with 32 planted OWASP vulnerabilities, so you can try the whole workflow legally.\n\nEverything is self-hosted and Apache-2.0 licensed. Scans, reports and evidence stay on your infrastructure, and analysis runs with your own LLM provider key.\n\nThree CVEs disclosed so far, found with BugTraceAI:\n\n| Product | CVE | CVSS | \n|---|---|---|\n| Wallos | CVE-2026-27479 | 7.7 High | \n| ZoneMinder | CVE-2026-27470 | 8.8 High | \n| Piwigo | CVE-2026-27834 | 7.2 High | \n\nThe project was presented on stage at DEF CON 34 (Las Vegas), RootedCON 2026 (Madrid) and HKOSCon 2026 (Hong Kong). Component versions are currently in beta — treat outputs as leads to verify, not verdicts. (That is the point of the evidence-first design.)\n\n*BugTraceAI is built for authorized security testing only. Only test applications you have explicit written permission to test.*", "url": "https://wpnews.pro/news/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester", "canonical_source": "https://dev.to/intelliflame/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester-4ln0", "published_at": "2026-10-07 03:33:36+00:00", "updated_at": "2026-10-07 03:47:51.736278+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "artificial-intelligence"], "entities": ["BugTraceAI", "BugStore", "DEF CON 34", "RootedCON 2026", "HKOSCon 2026", "Wallos", "ZoneMinder", "Piwigo"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester", "markdown": "https://wpnews.pro/news/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester.md", "text": "https://wpnews.pro/news/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester.txt", "jsonld": "https://wpnews.pro/news/meet-bugtraceai-an-open-source-self-hosted-agentic-pentester.jsonld"}}