❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 14 September 2026Main stream

Artificial Intelligence (AI) in Cybersecurity, Part 27: Web App Hacking with Cybermes

14 September 2026 at 10:10

Welcome back, aspiring cyberwarriors!

With so many AI tools out there, it’s getting harder to find the ones actually worth your time. A lot of projects look alike and the differences between them can come down to minor UI tweaks. But it’s still worth digging, because every now and then you find something good.

One of the interesting projects we came across recently is Cybermes. It’s an offensive security assistant and automation framework built for bug bounty hunting, recon and reporting. It has more than 200 security playbooks and full Model Context Protocol (MCP) support. The most notable thing here is the reporting structure. The framework handles reporting really well, it has a scope.yaml file you can modify and the TUI interface looks clean.

We’ll show what the assistant can do and how well it handles the tasks.

Setting Up

Unlike PentestCode, there’s some work to do before you can start using the tool.

First, make sure you have Go installed on your Kali. The framework needs to compile tools and without Go your installation will be incomplete.

kali > sudo apt update 
kali > sudo apt install go-lang

Then download the repository and run the setup script.

kali > git clone https://github.com/Zyrexnn/Cybermes.git
kali > cd Cybermes
kali > python3 -m venv venv; source venv/bin/activate
kali > chmod 777 setup.sh
kali > ./setup.sh

It’ll take a few minutes. When it’s done, run the doctor script to make sure everything is in order.

kali > python3 tools/doctor.py

After that, add your OpenRouter API key to two env files before you can start working with the tool.

kali > vim .env
kali > vim hermes/.env

Make sure you add the API key to both files, otherwise it won’t work.

kali > ./cybermes model

Finally, specify the scope in scope.yaml. We’ve got OWASP Juice Shop for the test, listening on port 3000.

Now we’re all set.

IDOR/BOLA – Terminal User InterfaceΒ 

The Terminal User Interface is clean and easy to work with, so we’ll start there. You might end up preferring it over the CLI version.

kali > TARGET=127_0_0_1_3000
kali > ./cybermes –tui

Our first prompt in TUI is hunting for IDOR using Nemotron 3.5 Lightning. As the model tests the target, you’ll see entries populating the screen with the commands the tool runs.

Fifteen minutes later we got our results and BOLA was confirmed.

Reporting is really the strongest side of this framework. It created a couple of files with reports and sorted them properly. As you keep hunting for bugs on the same target, all your findings get brought together in one file.

Findings are always stored in Markdown format and keep almost the same structure every time, which makes them look professional.

JWT & SQLi – Command-line InterfaceΒ 

Now let’s look at the CLI version and try to find more bugs.

kali > ./cybermes --cli

Our first prompt will be testing JWT:

Authorized lab only. Target http://127.0.0.1:3000/rest/user/login.
Audit authentication and JWT handling with non-destructive requests. Try the publicly documented Juice Shop demo accounts if needed (admin@juice-sh.op / admin123 and a normal user you register).

Check token claims, privilege flags, and whether a standard user can hit admin-ish REST routes.
Record only confirmed issues under reports/127_0_0_1_3000/findings/.

It took some time to reason through and test the app, then gave the results.

The same files were produced again, with PoCs and an explanation of each bug and the risks tied to it.

We also tested SQLi on search:

Authorized lab only. Audit http://127.0.0.1:3000/rest/products/search?q= for SQL injection using safe syntax and error/timing evidence. Do not dump the full database into the terminal. If confirmed, write reports/127_0_0_1_3000/findings/high_sqli_product_search.md and a minimal PoC in pocs/.

Here’s the report on our SQLi finding, looking just as good as the previous ones.

The tool passed all our tests against the Juice Shop and brought the findings together in the final report. The skills it ships with work well. You might want to go through them and add some of the ones we covered recently. We covered a repository with 83 skills and almost half of those were built by studying 681 real bug reports that people actually got paid for on HackerOne.

Summary

Cybermes has clear strengths. It’s good at reporting, it has a clean TUI and a big library of built in skills. The framework sets up quickly if you have Go installed on your Kali and it already knows which tools to work with based on those skills. That’s handy. We used OpenRouter for this test, but you can also point it at your local Ollama models. For that you’ll need a tool calling model (qwen2.5:14b). Chat only 3B models won’t cut it here.

We also invite you to join ourΒ AI for CybersecurityΒ training. During the training, we’ll show you different ways of using AI in cybersecurity, set up local models and solve labs. The field is evolving rapidly and the sooner you learn things, the greater the advantage you’ll have.

The post Artificial Intelligence (AI) in Cybersecurity, Part 27: Web App Hacking with Cybermes first appeared on Hackers Arise.

❌
❌