Research
From AI Agents to RCE - Building a Vulnerability Research Workflow - Quarkslab's blog
Publication date unknown · Discovered quarkslab.com
Page published
Publication date unknown · First observed: 9 Oct 2026
Coverage timeline
Single-source research — one report is available.
Why it matters
Quarkslab's agentic vulnerability-research harness demonstrates how AI agents can be assembled into a repeatable methodology that finds chainable RCE-class bugs in large codebases, signaling both a defensive accelerant and an offensive capability maturing rapidly.
Quarkslab describes an agentic AI harness built for vulnerability research that structures the process into staged pipelines (codebase exploration, analysis, validation, exploitation) over a queryable code graph. Applied to FreeRDP, the workflow surfaced two vulnerabilities that could be chained into remote code execution on the client, with a human researcher validating and guiding each step.