GitHub Security Lab disclosed an AI-assisted vulnerability discovery effort in which its open source Taskflow Agent generated candidate findings that researchers manually reproduced, triaged, assessed, and coordinated for disclosure, resulting in 18 public CVEs across eight open source projects. The affected software includes Quarkus, Docmost, Frappe, NocoDB, Sylius, Spree, Rocket.Chat, and Wekan, with the published issues tracked through GitHub Security Lab advisories.
The reported flaws were concentrated in access-control and web application logic weaknesses rather than memory-corruption bugs, highlighting the framework’s usefulness for finding application-layer security defects in widely used platforms. GitHub later described the broader approach publicly as an open source AI-powered framework for vulnerability scanning, while emphasizing that the disclosed CVEs represent only the subset of model-generated leads that were validated and released through the normal advisory process.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Bugflation reported that GitHub Taskflow Agent findings had produced 18 public CVEs across eight open source projects. The report highlighted that the disclosed issues were primarily access-control and web-application logic flaws rather than memory-corruption bugs.
GitHub published a blog post explaining how to scan for vulnerabilities using GitHub Security Lab’s open source AI-powered framework. The post contextualizes the methodology behind the vulnerability-finding approach referenced in later reporting on Taskflow Agent discoveries.
GitHub Security Lab published advisories covering vulnerabilities later summarized as 18 public CVEs across eight projects, including Quarkus, Docmost, Frappe, NocoDB, Sylius, Spree, Rocket.Chat, and Wekan. Bugflation states these advisories stemmed from AI-generated candidate reports that were manually reproduced, triaged, impact-assessed, and disclosed by Security Lab researchers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugflation.com
Open sourcegithub.blog
Open sourcesecuritylab.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.