Loading…
Loading…
Findings
Confirmed AI-contributed vulnerabilities. Open a finding to see the AI change, root cause, and minimum fix.
1–20 of 195 cases
gitpython-developers/gitpython
roskus/prospero-flow-crm
gitpython-developers/gitpython
go-git/go-git
gitpython-developers/gitpython
nearai/ironclaw
open-webui/open-webui
gitpython-developers/gitpython
fastify/fast-uri
arnasdon/wacrm
fission/fission
koxudaxi/datamodel-code-generator
fission/fission
fission/fission
koxudaxi/datamodel-code-generator
gitpython-developers/gitpython
open-webui/open-webui
budibase/budibase
microsoft/kiota
gitpython-developers/gitpython
| Advisory | Repository | Language | Root cause | AI contribution | AI tool | Published |
|---|---|---|---|---|---|---|
| GHSA-3WXW-XV34-2FRG | gitpython-developers/gitpython | Path & link handling | Incomplete remediation | 2026-08-10 | ||
| CVE-2026-59233 (GHSA-4FXP-2M36-QV64) | roskus/prospero-flow-crm | Authentication & access control | Incomplete remediation | 2026-08-10 | ||
| GHSA-5XXX-QHH7-9287 | gitpython-developers/gitpython | Injection & unsafe execution | Incomplete remediation | 2026-08-10 | ||
| CVE-2026-71556 (GHSA-HC8V-WWC9-VGXM) | go-git/go-git | Path & link handling | Incomplete remediation | 2026-08-07 | ||
| GHSA-WVPP-8HX9-P66J | gitpython-developers/gitpython | Injection & unsafe execution | Direct introduction | 2026-08-07 | ||
| CVE-2026-18980 (GHSA-CW23-QWR7-C655) | nearai/ironclaw | Injection & unsafe execution | Causal contribution | 2026-08-06 | ||
| CVE-2026-70485 (GHSA-8X5V-CPV7-8JJP) | open-webui/open-webui | Authentication & access control | Direct introduction | 2026-08-04 | ||
| GHSA-539M-9XH6-Q6RR | gitpython-developers/gitpython | Injection & unsafe execution | Incomplete remediation | 2026-08-03 | ||
| CVE-2026-18446 (GHSA-7P8R-X3MC-P8W7) | fastify/fast-uri | SSRF & network boundaries | Incomplete remediation | 2026-08-03 | ||
| GHSA-8JQH-598V-RFXC | arnasdon/wacrm | Validation & fail-open logic | Direct introduction | 2026-07-30 | ||
| CVE-2026-50569 | fission/fission | Authentication & access control | Direct introduction | 2026-07-28 | ||
| CVE-2026-55389 (GHSA-8359-H9FX-J6V9) | koxudaxi/datamodel-code-generator | Path & link handling | Flawed AI-written code | 2026-07-28 | ||
| CVE-2026-50570 (GHSA-QF5V-M7P4-95RP) | fission/fission | Validation & fail-open logic | Incomplete remediation | 2026-07-28 | ||
| CVE-2026-50568 (GHSA-R5JH-Q2MW-GCX4) | fission/fission | Validation & fail-open logic | New attack surface | 2026-07-28 | ||
| GHSA-RFR2-MQ9M-X2QX | koxudaxi/datamodel-code-generator | SSRF & network boundaries | Flawed AI-written code | 2026-07-28 | ||
| GHSA-3RP5-JJMW-4WV2 | gitpython-developers/gitpython | Injection & unsafe execution | Incomplete remediation | 2026-07-24 | ||
| CVE-2026-59221 (GHSA-FRVJ-C5QP-XJ4W) | open-webui/open-webui | Path & link handling | Incomplete remediation | 2026-07-24 | ||
| CVE-2026-73308 (GHSA-GH4H-34GR-87R7) | budibase/budibase | Authentication & access control | Direct introduction | 2026-07-24 | ||
| GHSA-P5RM-JG5C-8C77 | microsoft/kiota | Injection & unsafe execution | Incomplete remediation | 2026-07-24 | ||
| GHSA-R9MR-M37C-5FR3 | gitpython-developers/gitpython | Injection & unsafe execution | Incomplete remediation | 2026-07-24 |