工具介绍
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
# DeepAudit - 人人拥有的 AI 审计战队,让漏洞挖掘触手可及 ♂️
---
## 界面预览
审计流日志
实时查看 Agent 思考与执行过程
️ 智能仪表盘
一眼掌握项目安全态势
⚡ 即时分析
粘贴代码 / 上传文件,秒出结果
️ 项目管理
GitHub/GitLab/Gitea 导入,多项目协同管理
---
## CVE 漏洞发现
#### OpenClaw 漏洞挖掘成果
DeepAudit 内测版本对 [OpenClaw](https://github.com/openclaw/openclaw) 项目进行了深度安全审计,目前已发现 **6 个安全漏洞**,均已被官方确认并发布安全公告(GHSA)。漏洞类型覆盖命令注入、签名验证绕过、远程代码执行、凭证泄露、资源耗尽及敏感信息泄露,其中包含多个 High 级别漏洞。更多漏洞仍在持续挖掘中。
| GHSA 编号 | 项目 | 项目热度 | 漏洞类型 | 严重性 |
|:---|:---|:---:|:---|:----:|
| [GHSA-g353-mgv3-8pcj](https://github.com/advisories/GHSA-g353-mgv3-8pcj) | OpenClaw | [](https://github.com/openclaw/openclaw/stargazers) | Signature Verification Bypass | 8.6 |
| [GHSA-99qw-6mr3-36qr](https://github.com/advisories/GHSA-99qw-6mr3-36qr) | OpenClaw | [](https://github.com/openclaw/openclaw/stargazers) | Code Execution | 8.5 |
| [GHSA-7h7g-x2px-94hj](https://github.com/advisories/GHSA-7h7g-x2px-94hj) | OpenClaw | [](https://github.com/openclaw/openclaw/stargazers) | Credential Exposure | 6.9 |
| [GHSA-g2f6-pwvx-r275](https://github.com/openclaw/openclaw/security/advisories/GHSA-g2f6-pwvx-r275) | OpenClaw | [](https://github.com/openclaw/openclaw/stargazers) | Command Injection | Medium |
| [GHSA-jq3f-vjww-8rq7](https://github.com/openclaw/openclaw/security/advisories/GHSA-jq3f-vjww-8rq7) | OpenClaw | [](https://github.com/openclaw/openclaw/stargazers) | Resource Exhaustion | High |
| [GHSA-xwcj-hwhf-h378](https://github.com/openclaw/openclaw/security/advisories/GHSA-xwcj-hwhf-h378) | OpenClaw | [](https://github.com/openclaw/openclaw/stargazers) | Information Disclosure | Medium |
| CVE 编号 | 项目 | 项目热度 | 漏洞类型 | CVSS |
|:---|:---|:---:|:---|:----:|
| [CVE-2026-1884](https://nvd.nist.gov/vuln/detail/cve-2026-1884) | Zentao PMS | [](https://github.com/easysoft/zentaopms/stargazers) | SSRF | 5.1 |
| [CVE-2025-13789](https://nvd.nist.gov/vuln/detail/CVE-2025-13789) | Zentao PMS | [](https://github.com/easysoft/zentaopms/stargazers) | SSRF | 5.3 |
| [CVE-2025-13787](https://nvd.nist.gov/vuln/detail/CVE-2025-13787) | Zentao PMS | [](https://github.com/easysoft/zentaopms/stargazers) | Privilege Escalation | 9.1 |
| [CVE-2025-64428](https://nvd.nist.gov/vuln/detail/CVE-2025-64428) | Dataease | [](https://github.com/dataease/dataease/stargazers) | JNDI Injection | 9.8 |
| [CVE-2025-13246](https://nvd.nist.gov/vuln/detail/CVE-2025-13246) | Modulithshop | [](https://github.com/shsuishang/modulithshop/stargazers) | SQL Injection | 6.3 |
| [CVE-2025-64163](https://nvd.nist.gov/vuln/detail/CVE-2025-64163) | Dataease | [](https://github.com/dataease/dataease/stargazers) | SSRF | 9.8 |
| [CVE-2025-64164](https://nvd.nist.gov/vuln/detail/CVE-2025-64164) | Dataease | [](https://github.com/dataease/dataease/stargazers) | JNDI Injection | 9.8 |
| [CVE-2025-11581](https://nvd.nist.gov/vuln/detail/CVE-2025-11581) | PowerJob | [](https://github.com/PowerJob/PowerJob/stargazers) | Privilege Escalation | 7.5 |
| [CVE-2025-11580](https://nvd.nist.gov/vuln/detail/CVE-2025-11580) | PowerJob | [](https://github.com/PowerJob/PowerJob/stargazers) | Privilege Escalation | 5.3 |
| [CVE-2025-10771](https://nvd.nist.gov/vuln/detail/CVE-2025-10771) | Jimureport | [](https://github.com/jeecgboot/JimuReport/stargazers) | Deserialization | 9.8 |
| [CVE-2025-10770](https://nvd.nist.gov/vuln/detail/CVE-2025-10770) | Jimureport | [](https://github.com/jeecgboot/JimuReport/stargazers) | Deserialization | 6.5 |
| [CVE-2025-10769](https://nvd.nist.gov/vuln/detail/CVE-2025-10769) | H2o-3 | [](https://github.com/h2oai/h2o-3/stargazers) | Deserialization | 9.8 |
| [CVE-2025-10768](https://nvd.nist.gov/vuln/detail/CVE-2025-10768) | H2o-3 | [](https://github.com/h2oai/h2o-3/stargazers) | Deserialization | 9.8 |
| [CVE-2025-58045](https://nvd.nist.gov/vuln/detail/CVE-2025-58045) | Dataease | [](https://github.com/dataease/dataease/stargazers) | JNDI Injection | 9.8 |
| [CVE-2025-10423](https://nvd.nist.gov/vuln/detail/CVE-2025-10423) | Newbee-mall | [](https://github.com/newbee-ltd/newbee-mall/stargazers) | Guessable Captcha | 3.7 |
| [CVE-2025-10422](https://nvd.nist.gov/vuln/detail/CVE-2025-10422) | Newbee-mall | [](https://github.com/newbee-ltd/newbee-mall/stargazers) | Privilege Escalation | 4.3 |
| [CVE-2025-9835](https://nvd.nist.gov/vuln/detail/CVE-2025-9835) | Mall | [](https://github.com/macrozheng/mall/stargazers) | Privilege Escalation | 4.3 |
| [CVE-2025-9737](https://nvd.nist.gov/vuln/detail/CVE-2025-9737) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9736](https://nvd.nist.gov/vuln/detail/CVE-2025-9736) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9735](https://nvd.nist.gov/vuln/detail/CVE-2025-9735) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9734](https://nvd.nist.gov/vuln/detail/CVE-2025-9734) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9719](https://nvd.nist.gov/vuln/detail/CVE-2025-9719) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9718](https://nvd.nist.gov/vuln/detail/CVE-2025-9718) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9717](https://nvd.nist.gov/vuln/detail/CVE-2025-9717) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9716](https://nvd.nist.gov/vuln/detail/CVE-2025-9716) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9715](https://nvd.nist.gov/vuln/detail/CVE-2025-9715) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9683](https://nvd.nist.gov/vuln/detail/CVE-2025-9683) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9682](https://nvd.nist.gov/vuln/detail/CVE-2025-9682) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9681](https://nvd.nist.gov/vuln/detail/CVE-2025-9681) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9680](https://nvd.nist.gov/vuln/detail/CVE-2025-9680) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9659](https://nvd.nist.gov/vuln/detail/CVE-2025-9659) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9658](https://nvd.nist.gov/vuln/detail/CVE-2025-9658) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9657](https://nvd.nist.gov/vuln/detail/CVE-2025-9657) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9655](https://nvd.nist.gov/vuln/detail/CVE-2025-9655) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9646](https://nvd.nist.gov/vuln/detail/CVE-2025-9646) | O2oa | [](https://github.com/o2oa/o2oa/stargazers) | XSS | 5.4 |
| [CVE-2025-9602](https://nvd.nist.gov/vuln/detail/CVE-2025-9602) | RockOA | [](https://github.com/rainrocka/xinhu/stargazers) | Database Backdoor | 6.5 |
| [CVE-2025-9514](https://nvd.nist.gov/vuln/detail/CVE-2025-9514) | Mall | [](https://github.com/macrozheng/mall/stargazers) | Privilege Escalation | 3.7 |
| [CVE-2025-9264](https://nvd.nist.gov/vuln/detail/CVE-2025-9264) | Xxl-job | [](https://github.com/xuxueli/xxl-job/stargazers) | Privilege Escalation | 5.4 |
| [CVE-2025-9263](https://nvd.nist.gov/vuln/detail/CVE-2025-9263) | Xxl-job | [](https://github.com/xuxueli/xxl-job/stargazers) | Privilege Escalation | 4.3 |
| [CVE-2025-9241](https://nvd.nist.gov/vuln/detail/CVE-2025-9241) | Eladmin | [](https://github.com/elunez/eladmin/stargazers) | CSV/XLSX Injection | 7.5 |
| [CVE-2025-9240](https://nvd.nist.gov/vuln/detail/CVE-2025-9240) | Eladmin | [](https://github.com/elunez/eladmin/stargazers) | Sensitive Information Disclosure | 4.3 |
| [CVE-2025-9239](https://nvd.nist.gov/vuln/detail/CVE-2025-9239) | Eladmin | [](https://github.com/elunez/eladmin/stargazers) | Hardcoded Credentials | 3.7 |
| [CVE-2025-8974](https://nvd.nist.gov/vuln/detail/CVE-2025-8974) | Litemall | [](https://github.com/linlinjava/litemall/stargazers) | Hardcoded Credentials | 9.8 |
| [CVE-2025-8852](https://nvd.nist.gov/vuln/detail/CVE-2025-8852) | Wukong CRM | [](https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/stargazers) | Sensitive Information Disclosure | 4.3 |
| [CVE-2025-8840](https://nvd.nist.gov/vuln/detail/CVE-2025-8840) | Jsherp | [](https://github.com/jishenghua/jshERP/stargazers) | Privilege Escalation | 5.4 |
| [CVE-2025-8839](https://nvd.nist.gov/vuln/detail/CVE-2025-8839) | Jsherp | [](https://github.com/jishenghua/jshERP/stargazers) | Privilege Escalation | 8.8 |
| [CVE-2025-8764](https://nvd.nist.gov/vuln/detail/CVE-2025-8764) | Litemall | [](https://github.com/linlinjava/litemall/stargazers) | XSS | 5.4 |
| [CVE-2025-8753](https://nvd.nist.gov/vuln/detail/CVE-2025-8753) | Litemall | [](https://github.com/linlinjava/litemall/stargazers) | Arbitrary File Deletion | 5.4 |
| [CVE-2025-8708](https://nvd.nist.gov/vuln/detail/CVE-2025-8708) | White-Jotter | [](https://github.com/Antabot/White-Jotter/stargazers) | Deserialization | 7.5 |
[查看完整 CVE 列表详情](CVEList.md)
> *以上漏洞由 DeepAudit 团队成员 [@lintsinghua](https://github.com/lintsinghua) [@ez-lbz](https://github.com/ez-lbz) 使用 DeepAudit 挖掘发现*
> 如果您使用 DeepAudit 发现了漏洞,欢迎在 [Issues](https://github.com/lintsinghua/DeepAudit/issues/135) 中留言反馈。您的贡献将极大地丰富这份漏洞列表,非常感谢!
---
## ⚡ 项目概述
**DeepAudit** 是一个基于 **Multi-Agent 协作架构**的下一代代码安全审计平台。它不仅仅是一个静态扫描工具,而是模拟安全专家的思维模式,通过多个智能体(**Orchestrator**, **Recon**, **Analysis**, **Verification**)的自主协作,实现对代码的深度理解、漏洞挖掘和 **自动化沙箱 PoC 验证**。
我们致力于解决传统 SAST 工具的三大痛点:
- **误报率高** — 缺乏语义理解,大量误报消耗人力
- **业务逻辑盲点** — 无法理解跨文件调用和复杂逻辑
- **缺乏验证手段** — 不知道漏洞是否真实可利用
用户只需导入项目,DeepAudit 便全自动开始工作:识别技术栈 → 分析潜在风险 → 生成脚本 → 沙箱验证 → 生成报告,最终输出一份专业审计报告。
> **核心理念**: 让 AI 像黑客一样攻击,像专家一样防御。
## 为什么选择 DeepAudit?
---
## ️ 系统架构
### 整体架构图
DeepAudit 采用微服务架构,核心由 Multi-Agent 引擎驱动。
### 审计工作流
| 步骤 | 阶段 | 负责 Agent | 主要动作 |
|:---:|:---:|:---:|:---|
| 1 | **策略规划** | **Orchestrator** | 接收审计任务,分析项目类型,制定审计计划,下发任务给子 Agent |
| 2 | **信息收集** | **Recon Agent** | 扫描项目结构,识别框架/库/API,提取攻击面(Entry Points) |
| 3 | **漏洞挖掘** | **Analysis Agent** | 结合 RAG 知识库与 AST 分析,深度审查代码,发现潜在漏洞 |
| 4 | **PoC 验证** | **Verification Agent** | **(关键)** 编写 PoC 脚本,在 Docker 沙箱中执行。如失败则自我修正重试 |
| 5 | **报告生成** | **Orchestrator** | 汇总所有发现,剔除被验证为误报的漏洞,生成最终报告 |
### 项目代码结构
```
…
```
---
## 快速开始
### 方式一:一行命令部署(推荐)
使用预构建的 Docker 镜像,无需克隆代码,一行命令即可启动:
```bash
curl -fsSL https://raw.githubusercontent.com/lintsinghua/DeepAudit/v3.0.0/docker-compose.prod.yml | docker compose -f - up -d
```
## 国内加速部署(作者亲测非常无敌之快)
使用南京大学镜像站加速拉取 Docker 镜像(将 `ghcr.io` 替换为 `ghcr.nju.edu.cn`):
```bash
# 国内加速版 - 使用南京大学 GHCR 镜像站
curl -fsSL https://raw.githubusercontent.com/lintsinghua/DeepAudit/v3.0.0/docker-compose.prod.cn.yml | docker compose -f - up -d
```
手动拉取镜像(如需单独拉取)(点击展开)
```bash
# 前端镜像
docker pull ghcr.nju.edu.cn/lintsinghua/deepaudit-frontend:latest
# 后端镜像
docker pull ghcr.nju.edu.cn/lintsinghua/deepaudit-backend:latest
# 沙箱镜像
docker pull ghcr.nju.edu.cn/lintsinghua/deepaudit-sandbox:latest
```
> 镜像源由 [南京大学开源镜像站](https://mirrors.nju.edu.cn/) 提供支持
配置 Docker 镜像加速(可选,进一步提升拉取速度)(点击展开)
如果拉取镜像仍然较慢,可以配置 Docker 镜像加速器。编辑 Docker 配置文件并添加以下镜像源:
**Linux / macOS**:编辑 `/etc/docker/daemon.json`
**Windows**:右键 Docker Desktop 图标 → Settings → Docker Engine
```json
{
"registry-mirrors": [
"https://docker.1ms.run",
"https://dockerproxy.com",
"https://hub.rat.dev"
]
}
```
保存后重启 Docker 服务:
```bash
# Linux
sudo systemctl restart docker
# macOS / Windows
# 重启 Docker D