How it works
Advisory to runnable proof, autonomously.
Analyze the advisory
An AI agent reads the GHSA or CVE, pulls the vulnerable package, and understands the vulnerability's root cause.
Reproduce in a sandbox
The agent builds a faithful copy of the affected software and fires the exploit, capturing the crash, the leak, or the shell.
Publish verifiable proof
A self-contained script, a session replay, and a permanent REPRO ID. Run pruva-verify to see it fire yourself.
Latest
Verified Reproductions
Traefik digestAuth middleware gives empty secret to unknown usernames → auth bypass
Jenkins remember-me session fixation — attacker-plantable cookie value not rotated after login (SECURITY-4069)
Jenkins Stapler: CSRF crumb exposed in dynamically generated JavaScript endpoint (SECURITY-3607)
Jenkins Stapler form binding instantiates arbitrary config types → RCE (SECURITY-3966)
curl: domain-scoped cookie for a public suffix (e.g. Domain=co.uk) leaks to sibling subdomains despite libpsl
curl: Secure cookie attribute bypass when a TAB character precedes the Secure attribute in Set-Cookie
The identifier
Why REPRO IDs?
Verified Proof
Each reproduction includes executable scripts, session replays, and before/after evidence proving the vulnerability exists.
Permanent Citation
REPRO IDs are permanent, citable references. Link CVEs, GHSAs, and issues to verified reproductions.
Full Transparency
Watch session replays showing exactly how the agent reproduced the issue. Nothing hidden, everything auditable.
Cite it
Embed in Your README
Show that your security advisory has been independently verified with an embeddable badge.
Don't take the advisory's word for it. Run it.
Browse the full catalog of autonomously reproduced vulnerabilities — each with a runnable proof and a permanent REPRO ID.
Browse All Reproductions →