All systems

ZeroPath Platform

ZeroPath AI SAST

ZeroPath's AI-native SAST and security-research workflow, with public CVE-backed and upstream-patched findings across ProFTPD, Spinnaker, better-auth, FFmpeg, sudo, and other open-source projects.

8
Indexed entries
14
CVE IDs tracked
8
Critical/high entries
88%
Evidence index

ZeroPath Wall of Fame: 47 fixed public records. Fixed-record count checked July 20, 2026. Pending disclosures and unpatched reports are not automatically indexed. Open tracker.

What it is

ZeroPath describes its product as an AI-native code security platform and AI-native SAST rather than a rules-only static analyzer. Its public technical overview describes a pipeline that builds source-code structure, enriches call graphs, uses AI to identify sources and sinks, runs threat-model and validation agents, and can generate patches.

For Bugflation, the important part is narrower: ZeroPath has public research posts where its scanner, AI-assisted SAST, or ZeroPath Research workflow is named in the discovery story, and several of those findings are corroborated by CVE records, GitHub security advisories, upstream releases, or patch links.

What is verified

The current ledger indexes eight conservative ZeroPath entries:

What is held out

ZeroPath’s public Wall of Fame is broader than the indexed subset. It lists fixed vulnerabilities and pending disclosures, and the ZeroPath blog also describes 170 valid curl bug reports. Those are useful context, but Bugflation does not treat every correctness or cleanup report as a security finding.

The curl work is strong evidence that maintainers found ZeroPath output useful, but the public article mixes security issues, correctness bugs, compliance bugs, and cleanup work. It belongs in the system profile, not as 170 vulnerability findings. The broader set of 36 sudo fixes is also held out as a bulk count; Bugflation indexes only the exec_mailer issue because there is direct upstream attribution and independent CrackArmor context. Currently unpatched research, such as the public RAGFlow post, is also held until there is maintainer acceptance, a patch, or an advisory trail.

Why it matters

ZeroPath is an example of bugflation pressure outside the frontier-model lab setting. The public record shows AI-assisted vulnerability discovery attached to real projects, real patches, and CVE-backed advisories across deployment systems, authentication libraries, media tooling, FTP infrastructure, and security utilities.

The attribution is mixed. Most entries are self-reported: ZeroPath supplies the AI workflow claim, while independent records corroborate the vulnerability and fix. The sudo exec_mailer entry is stronger because the upstream commit names the ZeroPath AI Security Engineer directly. Both styles are publishable under Bugflation’s methodology, as long as the attribution label stays honest.

Sources

Attributed findings

Catalogued entries credited to ZeroPath AI SAST.

ID Title System Disclosed Severity
CVE-2026-43617 + 6 more ZeroPath public research adds seven CVEs and one reserved Monaco report Authorization bypass, session hijacking, RCE, denial-of-service, and local file inclusion - self-reported ZeroPath AI SAST (self-reported) May 20, 2026 critical CVE-2026-39816 ZeroPath finds Apache NiFi Execute Code permission bypass CVE-2026-39816 Authorization bypass leading to server-side code execution - self-reported ZeroPath AI SAST (self-reported) May 7, 2026 high CVE-2026-42167 ZeroPath finds ProFTPD mod_sql CVE-2026-42167 SQL injection in FTP SQL logging and authentication paths - self-reported ZeroPath AI SAST (self-reported) Apr 28, 2026 high CVE-2026-32604, CVE-2026-32613 ZeroPath discloses two critical Spinnaker RCE CVEs Command injection and Spring Expression Language code injection in deployment services - self-reported ZeroPath AI SAST (self-reported) Apr 20, 2026 critical CVE-2025-68246, CVE-2025-68811 Linux fixes credit ZeroPath on ksmbd and svcrdma CVEs Remote resource exhaustion and memory-copy boundary error - direct ZeroPath AI SAST (direct) Jan 13, 2026 high zeropath-ffmpeg-seven-memory-safety-fixes ZeroPath AI SAST reports seven FFmpeg memory-safety fixes Memory-safety and protocol logic vulnerability cluster - self-reported ZeroPath AI SAST (self-reported) Dec 2, 2025 high zeropath-sudo-exec-mailer-crackarmor ZeroPath AI Security Engineer credited on sudo exec_mailer fix Incomplete privilege drop in sudo mailer execution - direct ZeroPath AI SAST (direct) Nov 8, 2025 high CVE-2025-61928 ZeroPath scanner finds better-auth API key takeover CVE-2025-61928 Authentication bypass in API key creation and update routes - self-reported ZeroPath AI SAST (self-reported) Oct 19, 2025 high