discovered 03 Aug 2026
dianxing
→ View on GitHubDianXing (点星) is an AI-driven end-to-end code security auditing system that autonomously identifies and verifies vulnerabilities in source code without human intervention, offering a structured output of detected issues. Unlike traditional SAST tools, it employs semantic understanding to uncover deep vulnerabilities, such as authentication bypass and privilege escalation, which are often missed by conventional scanners. The system has demonstrated the ability to autonomously exploit zero-privilege remote code execution vulnerabilities, reinforcing the need for responsible disclosure of its capabilities.