DCODX.AI – Lessons learned and more CVEs

In this post, we continue sharing the results of our ongoing testing of the DCODX.AI harness. Over the past few months, we have been testing and refining the capabilities of our internal DCODX.AI platform. A significant part of this work involved refactoring the codebase to support multiple models and inference providers, reducing token usage (those […]
From Detection to Exploitation: How DCODX.AI Identified CVE-2026-22033

In this post, we disclose one of the first CVEs we identified after introducing DCODX.AI, our internal agentic whitebox pentesting tool we use to support our researchers and testers. DCODX.AI leverages a GraphRAG-based architecture to: Ground reasoning in application structure Model entry points and reachability Analyze privilege transitions Identify composable weaknesses Rather than asking whether […]