Hello World
My research focuses on LLM and AI agent security, particularly where these systems intersect with binary exploitation and systems security.
This page lists publicly disclosed vulnerabilities I have reported, together with selected awards.
Research covered by NDAs or other confidentiality obligations is omitted.
Year – 2021
Chromium:
- CVE-2021-37972: Out-of-bounds read in libjpeg-turbo
LibRaw:
- CVE-2021-38235: Heap buffer overflow in
fp_dng.cpp - CVE-2021-38236: Heap buffer overflow in
raw2image.cpp
Suwell OFD Reader:
- CNNVD-202111-2224-2225: Integer overflow leading to a buffer overflow in
pdfdom.dll - CNVD-2022-00039–00048: Uncontrolled resource consumption in
suwellofdapp.exe - CNVD-2022-00049: Arbitrary memory access in
swd20.dll
Year – 2022
Chromium:
- Issue 1312736, Issue 1327884: Null-dereference in PDFium
- Issue 1314658: Heap use-after-free in PDFium’s
CPDFSDK_AppStream::Write
Year – 2025
Tianwang Cup (National AI Security Challenge):
- First Place: Large Language Model Track
Year – 2026
Tianfu Cup:
- Champion: General AI Infrastructure Framework
OpenClaw:
- CVE-2026-33577: Privilege escalation via a
callerScopesbypass innode.pair.approve - CVE-2026-33578: Sender allowlist bypass via a group policy downgrade in Google Chat and Zalouser
- CVE-2026-33579: Privilege escalation via a scope bypass in
/pair approve - CVE-2026-33581: Arbitrary file read via the
mediaparameter in the message tool - CVE-2026-34503: Privilege persistence via a stale WebSocket session after token revocation
- CVE-2026-34504: SSRF in the
falprovider’s image download flow - CVE-2026-41296: Sandbox escape via a TOCTOU race in the FS bridge’s
readFileoperation - CVE-2026-41297: SSRF via unrestricted redirects in Marketplace plugin downloads
- CVE-2026-41329: Sandbox escape via context inheritance in Heartbeat
- CVE-2026-41352: Host RCE via a scope gate bypass during device pairing
- CVE-2026-41364: Arbitrary file write via a symlink in SSH sandbox tar uploads
- CVE-2026-41374: Resource exhaustion in Discord audio preflight transcription
- CVE-2026-41378: Gateway RCE via unrestricted agent dispatch in
node.event - CVE-2026-41397: Sandbox escape via symlink traversal in OpenShell Mirror Sync
PraisonAI:
- CVE-2026-40157: Arbitrary file write via path traversal during recipe extraction
- CVE-2026-40160: SSRF via an unvalidated URL in the HTTPX fallback for
web_crawl
Cherry Studio:
- CVE-2026-40501: RCE via malicious search provider content

Hello World
https://mundi-xu.github.io/2018/10/25/hello-world/