pexels tima miroshnichenko 5380589

VulnHuntr: LLM-Powered Static Analysis for Finding Zero-Days

Most vulnerability scanners look for patterns. They search for known bad strings in source code, compare library versions against a CVE database, or check for common misconfigurations. VulnHuntr takes a fundamentally different approach: it uses a large language model to trace the full execution path from user input to security-sensitive operations, understanding context and logic the way a human code reviewer would – but at machine speed.

What Makes VulnHuntr Different

Traditional static analysis tools use AST parsing and pattern matching. They’re fast for known patterns, but miss context-dependent vulnerabilities – where a vulnerability only exists because of how multiple components interact.

VulnHuntr, by Protect AI, uses Claude or GPT-4 to reason about code paths. It traces the flow from user-controlled input (HTTP parameters, form fields, file uploads) through the application to security-sensitive sinks (file system operations, database queries, OS commands). The LLM understands that user_input flowing through three layers of helper functions into an os.system() call represents RCE, even if no individual function looks dangerous in isolation.

Supported Vulnerability Classes

  • LFI – Local File Inclusion
  • RCE – Remote Code Execution
  • SSRF – Server-Side Request Forgery
  • AFO – Arbitrary File Overwrite
  • XSS – Cross-Site Scripting
  • IDOR – Insecure Direct Object Reference
  • SQLi – SQL Injection

Installation

git clone https://github.com/protectai/vulnhuntr
cd vulnhuntr

python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt

# Set API key (Claude recommended)
export ANTHROPIC_API_KEY=your_key_here

# Or for local Ollama (no API cost)
ollama pull qwen2.5-coder:32b

Basic Usage

# Analyse a single file
python vulnhuntr.py -r /path/to/project -f app.py

# Analyse entire repository
python vulnhuntr.py -r /path/to/project

# Specify LLM provider
python vulnhuntr.py -r /path/to/project --llm claude
python vulnhuntr.py -r /path/to/project --llm ollama --ollama-model qwen2.5-coder:32b

# Target specific vulnerability types
python vulnhuntr.py -r /path/to/project --vuln-types rce,sqli,ssrf

# Save output
python vulnhuntr.py -r /path/to/project -o /tmp/vulnhuntr_report.json

Understanding the Output

{
  "file": "app/views/file_handler.py",
  "line": 47,
  "vulnerability_type": "LFI",
  "confidence": "high",
  "description": "User-controlled filename parameter flows through path_join() to open() without sanitization",
  "poc": "GET /download?file=../../../../etc/passwd",
  "remediation": "Validate filename against an allowlist and use os.path.basename()"
}

The PoC is particularly valuable – VulnHuntr generates an actual test payload you can verify with, not just a theoretical description.

Connecting to Ollama for Local Analysis

# Start Ollama
ollama serve

# Pull a capable coding model
ollama pull qwen2.5-coder:32b   # Best results, needs 20GB+ RAM
ollama pull qwen2.5-coder:14b   # Good balance, needs 10GB RAM

# Run VulnHuntr against Ollama
python vulnhuntr.py -r /path/to/project 
                    --llm ollama 
                    --ollama-model qwen2.5-coder:32b 
                    --ollama-url http://localhost:11434

What It Finds That Other Tools Miss

VulnHuntr has found documented zero-days in production open-source Python projects. The types of issues it catches:

  • User input sanitised in one layer but used unsanitised in a different call path
  • Race condition vulnerabilities where file path validation and file access are separate operations
  • SSRF via indirect URL construction from user-controlled parameters
  • IDOR where object IDs are derived from encrypted/hashed user data that can be predicted

Limitations

VulnHuntr is Python-only as of 2026. PHP, JavaScript, Go, and other languages aren’t supported. For PHP codebases, traditional tools like Psalm and PHPStan with security plugins remain necessary. Very large monorepos can also exceed context window limits.

Integrating into Your Workflow

# 1. Run pattern-matching tools first
semgrep --config=p/python /path/to/project
bandit -r /path/to/project

# 2. Run VulnHuntr for context-aware analysis
python vulnhuntr.py -r /path/to/project -o /tmp/vulnhuntr.json

# 3. Manually review high-confidence findings
# 4. Verify PoCs in a safe environment before reporting

Conclusion

VulnHuntr demonstrates what LLM-assisted code review can deliver beyond what pattern-matching tools provide. The combination of call chain tracing and contextual reasoning catches a class of vulnerabilities that are genuinely hard to find any other way. For penetration testers and security researchers conducting code review engagements, it deserves a place in the standard toolkit alongside Semgrep and Bandit.


Leave a Reply