argo findings
Argo · real-world validation

Bugs found by reading the code, disclosed in the open.

Every vulnerability below was surfaced by Argo, an LLM-native static auditor, then hand-verified and reported upstream: as a public pull request or a published security advisory. Follow any link to the fix or advisory itself.

15
Projects
53
Public PRs
53
Already resolved
5
Languages (of many)
3
CVEs assigned
Scope Only findings that are already publicly disclosed are listed, each linking to its upstream pull request or published security advisory. Findings still under coordinated (private) disclosure are omitted until they go public. Argo itself is language-agnostic and has audited well beyond the languages shown here.
Recognition Credited on LiveKit's Security Hall of Fame. The disclosure itself was private, but the findings below that are now confirmed fixed each link to a real, public upstream pull request. The PRs don't individually name the reporter; the Hall of Fame page is where that credit lives. The remaining reported findings stay off this list until they're fixed too.

Disclosures

merged fixes first · then open review
Severity
Status
Language
Stars
Open-source C implementation of the OPC UA industrial communication stack.
6 merged
Open-source Go backend: SQLite database, auth and admin dashboard in one file.
1 advisory
Self-hosted music streaming server, Subsonic-API compatible.
3 advisories
Zero-dependency real-time media server & proxy (RTSP, RTMP, HLS, WebRTC, SRT, MoQ).
1 advisory
legbaRust
A fast, modern credential brute-forcer and password sprayer.
5 merged
halloyRust
A modern IRC client.
3 merged2 open
The CubeSat Space Protocol: a small network stack used on spacecraft and embedded systems.
1 merged
A lightweight MQTT broker.
6 merged
A compact C engine for running DeepSeek-class LLMs with an agent / tool loop.
10 resolved
    PR #539 Fix pre-auth double-free in the JSON request parser (applied via commit 8e49a5c, co-authored with antirez) Criticaldouble-free Merged upstream merged ↗
    PR #542 Bound file-declared length prefixes in the model loader (applied via commit c7689db, co-authored with antirez, alongside #543 and #545) Highheap overflow Merged upstream merged ↗
    PR #543 Cross-check tensor data size against shape in FP8/FP4 dequant (applied via commit c7689db, co-authored with antirez, alongside #542 and #545) Mediumout-of-bounds read Merged upstream merged ↗
    PR #544 Cap file-declared lengths in agent KV-cache reads (applied via commit 0fa15c6, co-authored with antirez) Mediummemory DoS Merged upstream merged ↗
    PR #545 Bound GGUF metadata / tensor counts by file size before allocating (applied via commit c7689db, co-authored with antirez, alongside #542 and #543) Mediumresource exhaustion Merged upstream merged ↗
    PR #546 Reject an oversized snapshot token_count before allocating (applied via commit f02d79c, co-authored with antirez) Lowdistributed DoS Merged upstream merged ↗
    PR #547 Make tool-output validation O(n) instead of O(n²) (pre-auth CPU DoS) (applied via commit a169cff, co-authored with antirez) Mediumalgorithmic DoS Merged upstream merged ↗
    PR #548 Bound tokenizer merges count to INT32_MAX like the tokens table (antirez/ds4#548 itself is still open upstream; adopted with authorship preserved into the community fork elkaix/ds4) Lowinteger bound Merged in fork ↗
    PR #541 Handle NaN in json_int() (undefined double→int cast) (applied via commit 8340f35, co-authored with antirez) Lowundefined behavior Merged upstream merged ↗
    PR #? Unlink the bash-tool output temp file on job cleanup (antirez/ds4#540 itself is still open upstream; adopted with authorship preserved into the community fork elkaix/ds4) Lowresource cleanup Merged in fork ↗
    Issue #549 Follow-up hardening / design items from a security review hardening notes Issue
A C implementation of the GGUF model-file format used by llama.cpp / ggml.
3 open PRs
Reconstructs and recovers files from damaged NTFS file systems.
2 merged
authentikPython
A self-hosted identity provider (SSO) implementing SAML, OAuth2/OIDC, LDAP and SCIM.
2 advisories
A widely-deployed TURN and STUN relay server for WebRTC NAT traversal.
2 advisories
Open-source, self-hostable WebRTC infrastructure (SFU) for real-time audio, video, and data.
14 fixed
Simple HTTP-based pub-sub notification service — send push notifications via a plain PUT/POST, no app-specific setup.
1 open PR

No findings match the current filters.

Contribute

open to reports and PRs

Contribute

Found a false positive, a bug Argo missed, or want to sharpen a prompt? Reports and pull requests are genuinely welcome, the false-positive and false-negative reports most of all. Found a real vulnerability with Argo, or one it missed? Report it, and you'll be credited right here next to the finding.