AISLE found six curl CVEs days after OpenAI Codex Security and Anthropic Mythos both reported zero on the same codebase
Stanislav Fort published on 2026-09-02 that AISLE's autonomous system produced 29 reports against curl after curl founder Daniel Stenberg had publicly posted on 2026-08-24 that Mythos 'can't find any more' and Codex security 'shows an empty list.' Six of the 29 were accepted by curl's security team and assigned CVEs in curl 8.22.0 (CVE-2026-80229 through 82209, covering an OpenSSL provider use-after-free, a pinning bypass, CA-store connection reuse, a tab-based secure-attribute bypass, a wolfSSL CA-cache callback override, and a domain-scoped public-suffix cookie bug); all six are rated Low severity. The methodological point matters more than the count: the zero-result baseline was public and timestamped before AISLE ran, and curl's maintainers, not the vendor, decided what counted, which is rare for AI security claims.
Source
↳ Follow the thread