mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-08-15 22:20:21 +02:00
feat(3.6.7): CVE exploitation pipeline, PoC-in-report, any-primitive chaining, --only, whitebox doctrine (#41)
Version 3.6.6 -> 3.6.7. +5 agents (430 -> 435). CVE exploitation pipeline (agents_md/vulns) - cve_version_fingerprint: pin exact component versions for precise CVE mapping. - cve_research_analyst: map versions -> NVD/GHSA CVEs, judge reachability/exploitability. - cve_poc_finder: locate/vet/adapt a public PoC, run non-destructively. - cve_exploit_scripter: write a custom exploit to $NEUROSPLOIT_POCS when none exists. Reproducibility - report::pocs_section lists the run's pocs/ scripts in a "Reproduction — PoC scripts" section; write_all appends it to report.md. Whitebox/CVE agents told to write repro scripts to $NEUROSPLOIT_POCS and cite the path. Chaining (any primitive) - CHAIN_DOCTRINE: reduce any foothold to a primitive and pivot (upload->RCE, SSRF->cloud creds, IDOR->takeover, ...), reuse looted creds, reason about business logic. New chain_cve_to_rce_to_pivot recipe. Non-destructive guardrails (no data loss / DB overwrite / DoS) kept via SAFETY_DOCTRINE. Re-test one vuln - --only <agent> on run/whitebox/greybox sets cfg.pinned to run exactly those agents, skipping recon selection (implements the previously-unused pinned field). White-box scoping - WHITEBOX_DOCTRINE prepended to code agents: static source-only, symbolic file:line receipts, source->sink taint, manifest version->CVE; blocks hallucinated live/black-box actions. Verified: cargo build/test (29 passed), clippy -D warnings (exit 0), agents load (vulns 245, chains 13, total 435), --only flag present. Claude-Session: https://claude.ai/code/session_01QDses7zTSa9YF7pPRjphvh Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
76b56898d1
commit
cb19e2194d
+34
@@ -1,3 +1,37 @@
|
||||
# NeuroSploit v3.6.7 — Release Notes
|
||||
|
||||
**Release Date:** August 2026
|
||||
**Codename:** Chain & Exploit
|
||||
**License:** MIT
|
||||
**Credits:** Joas A Santos & Red Team Leaders
|
||||
|
||||
## Highlights
|
||||
|
||||
- **CVE exploitation pipeline — 4 new agents.** `cve_version_fingerprint` (pin
|
||||
exact versions) → `cve_research_analyst` (map to NVD/GHSA, judge reachability) →
|
||||
`cve_poc_finder` (locate/vet/adapt a public PoC) → `cve_exploit_scripter` (write
|
||||
a custom exploit when none exists). Focus: actually exploiting vulns that have
|
||||
CVEs, not just flagging versions.
|
||||
- **PoCs land in the run's `pocs/` folder and are listed in the report.** Every
|
||||
agent writes runnable proofs to `$NEUROSPLOIT_POCS`; the report gains a
|
||||
**"Reproduction — PoC scripts"** section so findings replay end-to-end.
|
||||
- **Chaining for any primitive.** New `CHAIN_DOCTRINE` + a `chain_cve_to_rce_to_pivot`
|
||||
recipe turn any confirmed foothold into the next step (upload→RCE, SSRF→cloud
|
||||
creds, IDOR→takeover, CVE→RCE→pivot), reusing looted creds and reasoning about
|
||||
**business logic** — strictly non-destructive (no data loss / DB overwrite / DoS).
|
||||
- **`--only <agent>` — re-test a single vulnerability.** Runs exactly the named
|
||||
agent(s), skipping recon selection. On `run` / `whitebox` / `greybox`; repeatable
|
||||
or comma/semicolon-separated. (Implements the previously-dead `pinned` allowlist.)
|
||||
- **White-box stays white-box.** A `WHITEBOX_DOCTRINE` keeps code agents in static
|
||||
source-review mode (symbolic `file:line` receipts, source→sink taint, manifest
|
||||
version→CVE) and blocks hallucinated live/black-box network actions; agents can
|
||||
emit a repro PoC.
|
||||
- **435 markdown agents** (was 430).
|
||||
|
||||
**Full changelog:** https://github.com/JoasASantos/NeuroSploit/compare/v3.6.6...v3.6.7
|
||||
|
||||
---
|
||||
|
||||
# NeuroSploit v3.6.6 — Release Notes
|
||||
|
||||
**Release Date:** August 2026
|
||||
|
||||
Reference in New Issue
Block a user