What it is
pwn.ai describes its system as an autonomous agentic penetration-testing and vulnerability-research platform. Bugflation counts only public disclosures with an independent vulnerability or vendor record.
What is verified
Chrome’s release notes directly credit pwn.ai for CVE-2026-14077. The platform also published technical details and a proof of concept for CVE-2025-54322, an unauthenticated root command-injection issue in XSpeeder SXZOS; the public CVE record corroborates the vulnerability while pwn.ai supplies the autonomous discovery attribution.
What is held out
Disputed or still-unfixed ImageMagick reports are not indexed. Public technical detail alone is not enough when maintainer acceptance and remediation status remain unresolved.