Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vcamper — PoC: identify silent security patches before CVE | Kitploit
Tools/GitHubGitHub/rndhouse/vcamper
Static AnalysisVulnerability AnalysisCode AnalysisInformation GatheringPapers & ResearchLearning & Education
GitHubrndhouse/vcamper

vcamper

PoC: identify silent security patches before CVE

View Repository
2121 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

VCamper

VCamper ("Version Camper") is a proof-of-concept CLI that reviews a Git commit range for likely silent security fixes.

Security fixes often reach public Git history before the advisory trail catches up. A maintenance-looking commit can carry enough evidence for a reviewer to infer the bug path and likely consequence.

VCamper turns that release-diff workflow into repeatable evidence collection. It gathers each candidate's patch and changed-file snapshots. It records a hotspot plan before asking an agent to screen and verify the commits most likely to matter.

Follow updates: x.com/rndhouse

Example

curl CVE-2025-0725

curl fixed CVE-2025-0725 in commit 76f83f0db23846e254d940ec7fe141010077eb88. The title content_encoding: drop support for zlib before 1.2.0.4 reads like compatibility maintenance. The fix landed in curl's GitHub repo on 2025-01-24 through PR #16079. curl published the advisory on 2025-02-05. That left about 12 days between public code and public advisory. Sources: curl advisory and curl PR #16079.

This command analyzes that fix commit by itself:

cargo run -- analyze \
  --repo /path/to/curl \
  --from 76f83f0db23846e254d940ec7fe141010077eb88 \
  --to 76f83f0db23846e254d940ec7fe141010077eb88 \
  --provider codex \
  --model gpt-5.4 \
  --screen-effort medium \
  --verify-effort high \
  --out /tmp/vcamper-curl-cve-2025-0725

VCamper flagged the commit as security-relevant with confidence 0.95. The finding traced the removed old-zlib gzip fallback to a remote client-side memory exhaustion path: a server could keep curl buffering attacker-controlled gzip header bytes until memory was exhausted. The verifier identified the relevant state as GZIP_UNDERFLOW; optional gzip header fields could keep missing their terminating NUL while curl kept reallocating and appending bytes to z->next_in.

The run used the public fix commit alone; the CVE text stayed out of the analysis. The finding matched the vulnerable old-zlib fallback path and reported the supported consequence as remote resource-consumption DoS. curl's advisory uses the broader CWE-680 classification.

wolfSSL CVE-2026-5194

wolfSSL fixed CVE-2026-5194 in commit abce5be989ccd0665e2b9445abb856886975dfd1 from PR #10131. The commit title was 20260403-WC_FIPS_186. This is a harder case than curl because the patch mixes FIPS 186 compliance work with test and verification changes. It touches ASN.1 and ECC code in wolfcrypt/src/. It also reaches TLS and PKCS#7 paths.

That commit shows why VCamper uses staged Codex passes. A broad prompt drifted toward one local bug story. The staged pipeline kept separate theories alive and surfaced three verified findings from the same commit:

  • a shared ASN.1 signatureAlgorithm / key-family binding flaw in ConfirmSignature
  • a direct pre-hash ECDSA verification bug on the public wrapper path
  • a broader composite signed-object verification theory that ties algorithm binding to shared ECDSA digest-policy enforcement

The composite finalist carries the main signal. The final staged run confirmed a 0.90 finding that signed-object verification let attacker-controlled signature OIDs steer ECDSA verification to mismatched or below-policy digests. The published CVE also emphasizes mixed EdDSA / ML-DSA enablement. VCamper landed in the same patch family. It preserved multiple theories and verified them independently. It also recovered the shared verification boundary.

This command shows the current prototype behavior on that commit:

cargo run -- analyze \
  --repo /path/to/wolfssl \
  --from abce5be989ccd0665e2b9445abb856886975dfd1 \
  --to abce5be989ccd0665e2b9445abb856886975dfd1 \
  --provider codex \
  --model gpt-5.4 \
  --screen-effort xhigh \
  --verify-effort xhigh \
  --inventory-focuses 0,1,3,4,9 \
  --out /tmp/vcamper-wolfssl-cve-2026-5194

That command uses a curated hotspot shortlist because the commit is unusually noisy. The run recovered the relevant patch family and a useful composite signed-object verification theory from a commit that reads like compliance churn. For hard crypto commits the prototype can recover shared trust boundaries. It can also keep multiple verified security stories alive. Closer CVE narrative matching needs stronger mixed-feature reasoning in later stages.

Usage

cargo run -- analyze \
  --repo /path/to/repo \
  --from <older-release-commit> \
  --to <newer-release-commit> \
  --provider codex \
  --model gpt-5.4 \
  --screen-effort medium \
  --verify-effort high \
  --out /tmp/vcamper-run

Requirements

  • Rust toolchain
  • git
  • One agent CLI:
    • codex
    • claude
Download Tool