Every night at 3AM, a cron job on my homelab server runs claude /cve-pipeline.
By morning, there are pull requests waiting. Each one is a working exploit check for a recent CVE, tested against a vulnerable instance, tested again against a patched instance, with WAF bypass variants for the most popular WAF setups.
In the morning I review the PRs, merge, deploy. Users get the new checks on their next scan.
I'm a solo founder. The whole thing runs on a $200/mo Claude Max subscription. 31 exploit checks produced in the first 4 days.
Why Claude Code
I tried the API approach first. Spent a week on prompt chains, state management, caching so I don't spend a full wage on API calls, tool routing, error handling, retry logic. It worked, barely. The context window was also a problem. I had to summarize the previous steps to fit in the context window.
Then I realized Claude Code already does all of that. Bash access, file reads, command execution, context management. I don't need an orchestrator. I need to describe each step in markdown and let Claude Code figure out the execution.
So I wrote 8 skills. Each of them describes one stage of the pipeline. Claude Code reads the skill, does the work, saves state to JSON on disk. The next skill picks up where the last one left off.
This is how I automated the whole process with claude /cve-pipeline.
The pipeline
The cron job processes 4-8 CVEs per night. Each one runs through 8 stages in about 85 minutes.
First, /cve-discover queries the NVD API for CVEs from the last 14 days, cross-references CISA KEV, and scores them. CISA KEV listing: +50 points. CVSS 9+: +30. Public PoC: +20. High EPSS: +15. Top 8 move forward.
Then /cve-triage finds the source repo on GitHub, pulls the patch commit, reads the diff. This is where Claude Code reads the actual code change and figures out what the vulnerability is.
/cve-classify walks a decision tree. HTTP exploitable? Destructive? Single request proves it? The answers determine what kind of check to write.
/cve-lab spins up two Docker containers on an isolated network. Vulnerable version and patched version. The patched container is the false positive guard.
/cve-exploit is the core step. Claude Code reads the patch diff, writes a TypeScript function that sends the exploit payload and checks the response, then tests it against both containers. Iterates up to 5 times. The bar: 5/5 on vulnerable, 0/5 on patched.
/cve-validate is the quality gate. It make sure that the TypeScript compiles, the tests pass, that the evidence describes the actual finding, and that the curl repro commands work against both instances.
/cve-harden adds WAF bypass variants. If the standard payload gets a 403 from Cloudflare, then it tries unicode escapes, junk padding, and UTF-16LE encoding. Each bypass is tested against both lab instances.
/cve-pr creates a branch, commits, pushes, opens a PR with validation evidence and repro commands. Finally, it cleans up the Docker lab.
React2Shell: the stress test
I used CVE-2025-55182 as the test case for the pipeline. CVSS 10.0. Unauthenticated RCE on React 19 Server Components. Gadget chain, multiple confirmation signals, three WAF bypass variants. If the pipeline could handle this one, it could handle anything simpler.
The skill prompt referenced the Assetnote and Miggo research. Claude Code read it, understood the RSC Flight protocol gadget chain, and wrote a check that sends a multipart POST exploiting __proto__ traversal to the Function constructor. The payload runs echo $((41*271)) on the server. "11111" in the response means code execution.
Then the harden stage noticed the standard payload got 403'd by Cloudflare and wrote three WAF bypasses:
Unicode escapes in the JSON ($ to \u0024, __ to \u005f\u005f). Flight parser decodes them back via JSON.parse(), but the raw bytes don't match WAF signatures. Gets past Cloudflare, AWS WAF, Akamai.
5MB junk field prepended before the payload. WAFs only inspect the first N bytes. Cloudflare Free stops at 1MB.
UTF-16LE encoding with charset header. Busboy decodes it, WAFs see null-interleaved garbage.
Tested against Cloudflare Pro: standard blocked, unicode bypass confirmed RCE. Vercel blocks everything with a purpose-built React2Shell WAF rule.
300 lines of TypeScript, written and validated without me touching a keyboard.
The automation shift
Everyone writes code with AI in 2026. That's not the interesting part. The interesting part is that I don't even open a terminal for this. The pipeline runs, I wake up to PRs, I review and merge. The work happened while I was asleep.
Last week it surfaced a path traversal in Nginx UI I'd never heard of and a SQL injection in a WordPress plugin with 200K installs. Both would have scrolled past me in the NVD feed. I woke up, reviewed the PRs, and they were solid.
This is where things are going for every company, not just security. The teams that figure out how to set up autonomous workflows, agents that do real multi-stage work unsupervised, will operate at a completely different scale than teams still using AI as a fancy autocomplete. Writing code is step one. Running entire pipelines without a human in the loop is step two, and most companies haven't started thinking about it.
Full list of checks at attackerview.com/checks/exploits.
If you want to try the scanner on your website, attackerview.com
