VulX Research

Proof, not press releases.

We publish the method, not a score. Every exploit we report is certified by a deterministic check rather than a model’s opinion — and where we cannot certify it, we say so instead of rounding it up.

Publications

One paper so far.

There will be more when there is more we can stand behind.

whitepaper-001 v1.0

Proving LLM-Found Authorization Bugs in AI-Generated Code

Minh Danh Ngo · June 2026

A model can find a suspicious route. It cannot tell you whether the route is actually reachable. This paper sets out the check that decides: an anonymous role reads a planted canary row inside a single transaction that is always rolled back, and the finding only counts if that read succeeds.

Authorization BOLA / IDOR Deterministic oracle AI-generated code

Nothing of yours is read. The transaction is rolled back either way.

Collaborate

Research is a field, not a moat.

If you are working on broken authorization, BOLA, or on proving exploits in generated code, we would rather compare notes than sit on ours.

  • 01Findings you think we should be able to certify, and cannot.
  • 02Cases where the check passes but the bug is real, which is the failure mode we care most about.
  • 03Datasets of generated code with known authorization holes.