CodeAnt discovers a Zip Slip bypass in patool's safe_extract
The vulnerability CVE-2026-29509 stems from using os.path.commonprefix instead of commonpath, allowing path traversal on Python <3.12.
See the latest news and media coverage for CodeAnt. We track all announcements, press releases, and industry mentions in real time, all in one place.
AI-powered code security and pentesting platform
codeant.aiLast updated
In short: CodeAnt secured $2M in funding and launched a unified security platform to automate offensive and defensive code analysis.
The vulnerability CVE-2026-29509 stems from using os.path.commonprefix instead of commonpath, allowing path traversal on Python <3.12.
The self-propagating worm compromised 314 packages in 22 minutes, stealing credentials and spreading via npm tokens.
Users open Claude Code, type a command, and receive full code reviews without tabs or copy-paste. It enables seamless AI-assisted coding.
They deliver results in 48 hours, charge only for high or critical vulnerabilities found, and provide free reports for clean systems. This aligns incentives with clients.
Learn about how we built a CI-native AI code reviewer using OpenCode that helps our engineers ship better, safer code.
California, May 07, 2025 (GLOBE NEWSWIRE) -- AI might be great at helping engineers write code, but it's creating a new problem – all that...
Track CodeAnt and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to CodeAnt and other trending companies.