Research

From AI Agents to RCE - Building a Vulnerability Research Workflow - Quarkslab's blog

Page published

Publication date unknown · First observed: 9 Oct 2026

Coverage timeline

9 Oct 2026quarkslab.comobserved

Single-source research — one report is available.

Why it matters

Quarkslab's agentic vulnerability-research harness demonstrates how AI agents can be assembled into a repeatable methodology that finds chainable RCE-class bugs in large codebases, signaling both a defensive accelerant and an offensive capability maturing rapidly.

Quarkslab describes an agentic AI harness built for vulnerability research that structures the process into staged pipelines (codebase exploration, analysis, validation, exploitation) over a queryable code graph. Applied to FreeRDP, the workflow surfaced two vulnerabilities that could be chained into remote code execution on the client, with a human researcher validating and guiding each step.