Scalable AI security review,
verified by humans.

Loopcheck is a research project helping organizations secure their codebases by using AI to find and review vulnerabilities at scale.

What we do

Vulnerability research

AI can now review code at a scale no human team can match. We point frontier models at entire codebases to surface candidate vulnerabilities, and a human researcher verifies each one, so what we report is confirmed, not speculative.

Much of our work focuses on open source software, and we contribute fixes upstream where feasible so the wider ecosystem benefits.

Knowledge sharing

We are open about how we work. We share our methods and lessons learned from using AI to find vulnerabilities in widely deployed software, and we work with teams who want to apply the same approach to their own code.

Approach

We try to review whole codebases if possible, including their transitive dependencies. The method works in two stages. First, an AI-assisted pipeline sweeps every repository at a scale no single auditor could cover by hand, and where possible builds a working PoC for each candidate. Second, a human researcher triages every candidate, discards the false positives, and traces each real bug to its root cause. Many candidates are discarded as not exploitable. The validation, the written report, and any fixes are led by humans, with AI helping along the way.


The outcome is a security report covering the components we review, a set of responsibly disclosed findings, and, where feasible, fixes contributed back to the project.

Track record

30+ CVEs and confirmed findings in software used by millions
58 merged open-source pull requests

The findings span browsers, infrastructure and developer tools, and range from memory-safety issues deep in C and C++ to web and injection bugs in JavaScript.

  • CVE-2026-8558 Google Chrome Out-of-bounds write in the font path allowing remote code execution inside the sandbox. Rated High, CVSS 8.8. Chrome VRP reward.
  • CVE-2026-4699 Mozilla Firefox Incorrect boundary conditions in Layout, Text and Fonts. Rated High, published as MFSA 2026-20.
  • CVE-2026-41148 Mermaid CSS injection from improper sanitization in the JavaScript diagramming library. Code injection, CWE-94. Fixed upstream.

Other confirmed findings include Keycloak, Apache ActiveMQ, Spotify, Rancher, Argo, Home Assistant, Sentry, NetworkManager, Gitea, Vim and others.

Team

Andrej

Vulnerability researcher

Penetration tester with 7 years of experience, focused on building AI pipelines that combine deterministic tooling and LLMs to find vulnerabilities in widely deployed software.

Matej

Vulnerability researcher

Security professional experienced in bug bounty and responsible disclosure programs, with a background in software development and code review.

Contact

Want us to review your codebase, discuss a research collaboration, or sponsor our work on specific open source projects? Email us and we will get back to you.