Capability
Incomplete fix detection: find the bug the patch missed.
Vorthix AI's XOR-1 agent reads a security patch as a claim about the code, then tests that claim. It maps every place the vulnerable behavior can still be reached and writes a PoC where the fix falls short. The method produced CVE-2026-56412 in libexpat and CVE-2026-57158 in FreeRDP.
- Method
- Treat the patch as a claim
- Published
- libexpat and FreeRDP
- Output
- A PoC for the bypass
The problem
A closed ticket is not a closed risk.
Fixes are usually written against the single input that triggered the original report. Variants that reach the same flaw by another route often remain.
Attackers know this and compare patches against the code for exactly that reason. Defenders rarely have time to do the same.
How XOR-1 works on this
From first hypothesis to a verified report.
- 01
Read the patch
XOR-1 extracts the assumption the fix relies on, such as a bound, a state check, or an ordering guarantee.
- 02
Map every call path
It traces each route that can still reach the vulnerable behavior, including ones the original report never touched.
- 03
Find the broken assumption
The agent looks for the one path where that assumption silently fails.
- 04
Demonstrate the bypass
It writes a PoC against the patched build and confirms the result dynamically.
What your team receives
A handoff engineers can act on.
- The exact path that still reaches the flaw
- A working PoC against the patched build
- An explanation of the assumption that broke
- A recommended complete fix with a regression test
- Verification by the Vorthix research team before delivery
Published work
Findings you can read in full.
Questions
Common questions.
What is an incomplete fix?
A patch that stops the reported trigger but leaves another route to the same underlying flaw.
Can XOR-1 check our own past CVEs?
Yes. Provide the advisories and fix commits for your product, and XOR-1 tests each one against the current code.
Does it apply to third-party libraries we depend on?
Yes. Dependencies your code reaches are in scope, and findings in upstream projects are disclosed to their maintainers.
How does this fit a continuous engagement?
A continuous engagement re-evaluates changes as they land, including security patches, so a fix is checked soon after it merges.
Keep exploring
More from Vorthix Sec.
Bring us the code that matters most.
Tell us about your software and we will scope the right engagement.