How it works
Advisory to runnable proof, autonomously.
Analyze the advisory
An AI agent reads the GHSA or CVE, pulls the vulnerable package, and understands the vulnerability's root cause.
Reproduce in a sandbox
The agent builds a faithful copy of the affected software and fires the exploit, capturing the crash, the leak, or the shell.
Publish verifiable proof
A self-contained script, a session replay, and a permanent REPRO ID. Run pruva-verify to see it fire yourself.
Latest
Verified Reproductions
bubblewrap: sandbox escape via /oldroot symlink traversal during setup — files created on host
Apache Log4j2 serialized LogEvent filter bypass to conditional RCE
Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640)
NLTK <3.10.3 RCE in AllowlistUnpickler — validates pickle module string but not global name; dotted-name traversal escapes allowlist to reach arbitrary callables
MLflow unauthenticated full-read SSRF in webhook delivery via redirect-follow bypass of _validate_webhook_url guard
Authenticated command injection in pm2panel's /restart handler allows remote shell command execution on the host.
The identifier
Why REPRO IDs?
Verified Proof
Each reproduction includes executable scripts, session replays, and before/after evidence proving the vulnerability exists.
Permanent Citation
REPRO IDs are permanent, citable references. Link CVEs, GHSAs, and issues to verified reproductions.
Full Transparency
Watch session replays showing exactly how the agent reproduced the issue. Nothing hidden, everything auditable.
Cite it
Embed in Your README
Show that your security advisory has been independently verified with an embeddable badge.
Don't take the advisory's word for it. Run it.
Browse the full catalog of autonomously reproduced vulnerabilities — each with a runnable proof and a permanent REPRO ID.
Browse All Reproductions →