Download
Install the local Companion.
Source-to-sink vulnerability research.
Prefer the terminal?
Prefer the browser?
vm2 · CVE-2026-47140
Enter owner/repository in the Workspace or CLI.
Eight disciplined phases in one warm session.
Validated findings, evidence, and a downloadable report.
Install the Companion once. Start scans, steer research, review findings, and download reports from the Workspace.
Open WorkspaceInstall the local Companion.
Connect it to your Workspace.
Run everything from the browser.
Public records, sorted by impact.
Report the outcome — or we auto-detect it from public GitHub advisories that credit you.
What converts, and what maintainers reject — distilled into new archetype and rejection rules.
The next release hunts smarter. Same tool, sharper edge.
Opt-in, always. We only ever see a finding's shape — class, archetype, CVSS — never your repository or the finding itself.
Outcomes are auto-verified from public advisories that credit your handle. No self-reporting.
Synced hourly from GitHub advisory credits.
Use the browser or run it from your terminal.
by Sneh Bavarva