logo

Sandyaa: Open-source autonomous security bug hunter

ID: e3d089b7-d4d6-5cd5-9cb0-3d7202d513e8

STIX ID: report--e3d089b7-d4d6-5cd5-9cb0-3d7202d513e8

Feed Name: Help Net Security

Threat Score
30/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Mirko Zorz

...
...

Sandyaa, an open-source LLM-powered autonomous security auditor from SecureLayer7, analyzes repositories by tracing data flows and generating confirmed vulnerability findings with Python proof-of-concepts (PoCs). The tool includes multiple recursive verification phases and an attacker-control filter to reduce false positives and only optionally executes PoCs; it has already surfaced two public bugs in Spring AI (a SQL injection and a JSONPath injection).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.