{
 "name": "YFarmX AI-Found Vulnerability Register",
 "homepage": "https://yfarmx.com/tools/ai-found-vulnerabilities/",
 "updated": "2026-09-19",
 "source": "CVE Program records read through the CVEProject/cvelistV5 mirror, GitHub advisories, the assigning CNA's own release notes and advisories, and the finder's own publication where no record carries the credit. Every row names the tier of evidence its attribution rests on and the date it was last checked.",
 "license": "CC BY 4.0",
 "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
 "attribution": "YFarmX, https://yfarmx.com",
 "method": "A row enters where a public artefact names both the vulnerability and the machine involvement. Attribution tiers, strongest first: credits-array (the CVE record's own credits field names the finder), cna-advisory (the assigning CNA credits the finder in its own advisory or release note), external-claim (the finder or a researcher claims the row against a record whose credits are empty or name people), claimed (an identifier quoted in public that the CVE Program's list does not yet serve), aggregate (a published count with no identifier list). Refresh: fetch each record from the mirror and read its credits array.",
 "lastChecked": "2026-09-19",
 "tiers": {
  "credits-array": "The CVE record's own credits field names the finder",
  "cna-advisory": "The assigning CNA credits the finder in its own advisory or release note",
  "external-claim": "The finder or a researcher claims the row; the record's credits are empty or name people",
  "claimed": "An identifier quoted in public that the CVE Program's list does not yet serve",
  "aggregate": "A published count with no identifier list"
 },
 "records": [
  {
   "id": "aifv-0060",
   "cve": null,
   "title": "Google OSS-Fuzz-Gen reports 30 new bugs found by automatically generated fuzz targets",
   "project": "OSS-Fuzz projects (cJSON, libplist, hunspell, zstd, gdbm, pjsip, gpac, sqlite3, openssl and others)",
   "component": null,
   "bugClass": "aggregate: 30 bugs, one with a CVE",
   "finder": "Google OSS-Fuzz-Gen",
   "finderOrg": "Google Open Source Security",
   "autonomy": "LLM-generated fuzz targets run on OSS-Fuzz",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "\"So far, we have reported 30 new bugs/vulnerabilities found by automatically generated targets built by this framework\"",
   "assigner": null,
   "date": "2026-09-12",
   "dateBasis": "README as read on 12 September 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "google/oss-fuzz-gen README",
     "url": "https://raw.githubusercontent.com/google/oss-fuzz-gen/main/README.md"
    }
   ],
   "summary": "The README table lists 23 named-project rows and seven undisclosed rows, two of them pending maintainer triage, totalling the 30 it claims. One entry carries a CVE, CVE-2024-9143, which is its own row here.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0060/"
  },
  {
   "id": "aifv-0066",
   "cve": null,
   "title": "Anthropic reports an autonomous exploit workflow yielding more than a dozen possible zero-days in a month",
   "project": "network appliances (unnamed)",
   "component": null,
   "bugClass": "aggregate: \"more than a dozen possible zero day findings in a single month\"",
   "finder": "GTG-10007 exploit workflow (threat actor)",
   "finderOrg": "Anthropic threat intelligence designation GTG-10007",
   "autonomy": "autonomous workflow iterating continuously, findings held privately by the actor",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "\"One workflow iterating continuously on network appliances yielded more than a dozen possible zero day findings in a single month.\"",
   "assigner": null,
   "date": "2026-09-09",
   "dateBasis": "report page created 9 September 2026 per its metadata",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "Anthropic, threat intelligence report, September 2026",
     "url": "https://www.anthropic.com/threat-intelligence-report-september-2026"
    }
   ],
   "summary": "Anthropic's September 2026 threat report describes an exploit foundry that ran firmware decryption through a decompiler tool server to tested exploit code, with findings the actor kept. \"Possible\" is the report's own word.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0066/"
  },
  {
   "id": "aifv-0047",
   "cve": "CVE-2026-87491",
   "title": "Chrome V8 out-of-bounds write exploited in the wild, found by a human researcher and paid $2,500 (the control row)",
   "project": "Google Chrome",
   "component": "V8",
   "bugClass": "out-of-bounds write",
   "finder": "Jihyeon Jeong (human researcher)",
   "finderOrg": "Compsec Lab, Seoul National University",
   "autonomy": "human",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "[$2,500][ 543557673 ] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06",
   "assigner": "Chrome",
   "date": "2026-09-08",
   "dateBasis": "release note",
   "severity": {
    "scale": "Chromium severity",
    "score": null,
    "rating": "Medium"
   },
   "bounty": {
    "paid": true,
    "amountUsd": 2500,
    "programme": "Chrome VRP"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/87xxx/CVE-2026-87491.json"
    },
    {
     "label": "Chrome Releases, Stable Channel Update, 8 September 2026",
     "url": "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html"
    }
   ],
   "summary": "Fixed in Chrome 153.0.8010.36 on 8 September 2026 and exploited in the wild by a third party. The row sits in the register as a control: headlines conflated it with an AI-derived exploit chain built on 3 September, and the release note credits a person, with a $2,500 reward.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0047/"
  },
  {
   "id": "aifv-0018",
   "cve": "CVE-2026-83596",
   "title": "WebKitGTK memory corruption in OpenTypeVerticalData, found by Google Big Sleep",
   "project": "WebKitGTK",
   "component": "OpenTypeVerticalData findFeature",
   "bugClass": "memory corruption",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "Red Hat would like to thank Google Big Sleep for reporting this issue.",
   "assigner": "Red Hat",
   "date": "2026-08-31",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 8.8,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/83xxx/CVE-2026-83596.json"
    }
   ],
   "summary": "A memory corruption in WebKitGTK from 1.10.0, assigned by Red Hat on 31 August 2026 with a Big Sleep acknowledgement, the newest Big Sleep record in the register.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0018/"
  },
  {
   "id": "aifv-0068",
   "cve": null,
   "title": "Anthropic attributes 500 or more high-severity vulnerabilities that survived decades of scrutiny to Claude Opus",
   "project": "open-source and partner codebases (unnamed)",
   "component": null,
   "bugClass": "aggregate: \"500 or more high-severity vulnerabilities\"",
   "finder": "Claude Opus (Anthropic)",
   "finderOrg": "Anthropic",
   "autonomy": "model-assisted discovery per Anthropic's cybersecurity page",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "\"found that survived decades of scrutiny and automated analysis\", filed under Claude Opus on Anthropic's cybersecurity page",
   "assigner": null,
   "date": "2026-08-21",
   "dateBasis": "YFarmX report of 21 August 2026 quoting the page",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "YFarmX, Claude Security now scans on Mythos 5",
     "url": "https://yfarmx.com/claude-security-scans-run-on-mythos-5/"
    }
   ],
   "summary": "A separate figure from the Glasswing count, filed under Claude Opus rather than Mythos, with no identifier list.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0068/"
  },
  {
   "id": "aifv-0067",
   "cve": null,
   "title": "Anthropic says Project Glasswing partners found more than 10,000 high- or critical-severity flaws",
   "project": "Glasswing partner codebases (about 200 organisations)",
   "component": null,
   "bugClass": "aggregate: \"more than 10,000 high- or critical-severity security flaws\"",
   "finder": "Claude Mythos Preview and Mythos 5 (Project Glasswing)",
   "finderOrg": "Anthropic",
   "autonomy": "partner organisations running the gated model over their own code",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "Anthropic post of 2 June 2026, as quoted in the YFarmX report of 21 August 2026",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "Anthropic post extending Glasswing, 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "YFarmX, Claude Security now scans on Mythos 5",
     "url": "https://yfarmx.com/claude-security-scans-run-on-mythos-5/"
    }
   ],
   "summary": "On 2 June 2026 Anthropic said it was extending Glasswing to about 150 more organisations and that partners had by then found more than 10,000 high- or critical-severity flaws. No identifier list accompanies the figure.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0067/"
  },
  {
   "id": "aifv-0061",
   "cve": null,
   "title": "depthfirst reports 21 FFmpeg zero-days from a $1,000 scan of 1.5 million lines",
   "project": "FFmpeg",
   "component": null,
   "bugClass": "aggregate: 9 identifiers claimed, 12 tracked as DFVULN-116 to DFVULN-127",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; each finding with a reproducible proof-of-concept input per the write-up",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "\"21 zero-day vulnerabilities in FFmpeg\" at a \"total cost of roughly $1k\" over \"roughly 1.5 million lines of heavily optimized C code\"",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "Opened on 19 September 2026: the page dates itself 2 June 2026, names nine CVE identifiers and twelve DFVULN identifiers, and says the twelve are fixed with no CVE assigned yet. The most severe, DFVULN-127, is described as a heap buffer overflow in the AV1 RTP depacketizer reachable from one 183-byte packet.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0061/"
  },
  {
   "id": "aifv-0056",
   "cve": "CVE-2026-39218",
   "title": "FFmpeg heap overflow in the DASH demuxer, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "DASH demuxer",
   "bugClass": "heap overflow, introduced in 2017",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0056/"
  },
  {
   "id": "aifv-0055",
   "cve": "CVE-2026-39217",
   "title": "FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "FFmpeg component per the write-up",
   "bugClass": "memory safety, class per the write-up",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0055/"
  },
  {
   "id": "aifv-0054",
   "cve": "CVE-2026-39216",
   "title": "FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "FFmpeg component per the write-up",
   "bugClass": "memory safety, class per the write-up",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0054/"
  },
  {
   "id": "aifv-0053",
   "cve": "CVE-2026-39215",
   "title": "FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "FFmpeg component per the write-up",
   "bugClass": "memory safety, class per the write-up",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0053/"
  },
  {
   "id": "aifv-0052",
   "cve": "CVE-2026-39214",
   "title": "FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "FFmpeg component per the write-up",
   "bugClass": "memory safety, class per the write-up",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0052/"
  },
  {
   "id": "aifv-0051",
   "cve": "CVE-2026-39213",
   "title": "FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "FFmpeg component per the write-up",
   "bugClass": "memory safety, class per the write-up",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0051/"
  },
  {
   "id": "aifv-0050",
   "cve": "CVE-2026-39212",
   "title": "FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "FFmpeg component per the write-up",
   "bugClass": "memory safety, class per the write-up",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0050/"
  },
  {
   "id": "aifv-0049",
   "cve": "CVE-2026-39211",
   "title": "FFmpeg integer overflow in the swscale, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "swscale",
   "bugClass": "integer overflow, introduced in 2010",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0049/"
  },
  {
   "id": "aifv-0048",
   "cve": "CVE-2026-39210",
   "title": "FFmpeg heap overflow in the MPEG-TS demuxer, claimed by depthfirst under an identifier the CVE list does not yet serve",
   "project": "FFmpeg",
   "component": "MPEG-TS demuxer",
   "bugClass": "heap overflow, introduced in 2010",
   "finder": "depthfirst autonomous security agent",
   "finderOrg": "depthfirst",
   "autonomy": "autonomous agent; reproducible proof-of-concept input per the write-up",
   "evidenceTier": "claimed",
   "creditsVerbatim": "no record: the identifier answers HTTP 404 at the cvelistV5 mirror",
   "assigner": null,
   "date": "2026-06-02",
   "dateBasis": "depthfirst write-up, published 2 June 2026",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": "FFmpeg pays no bounty"
   },
   "links": [
    {
     "label": "depthfirst, 21 zero-days in FFmpeg",
     "url": "https://depthfirst.com/research/21-zero-days-in-ffmpeg"
    }
   ],
   "summary": "One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine \"have already been assigned CVEs\"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.",
   "cveRecordStatus": "HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026",
   "confidence": "UNVERIFIED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0048/"
  },
  {
   "id": "aifv-0069",
   "cve": null,
   "title": "Google CodeMender upstreamed 72 security fixes in its first six months",
   "project": "open-source projects (unnamed), codebases up to 4.5 million lines",
   "component": null,
   "bugClass": "aggregate: 72 fixes, patching rather than discovery",
   "finder": "Google CodeMender",
   "finderOrg": "Google DeepMind",
   "autonomy": "agent proposes patches; every patch reviewed by a human researcher before submission",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "DeepMind announcement figure, corroborated across summaries; the announcement page was unopened by this desk",
   "assigner": null,
   "date": "2026-05-11",
   "dateBasis": "Google Threat Intelligence Group report of 11 May 2026 describing CodeMender",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "Google DeepMind, Introducing CodeMender",
     "url": "https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/"
    }
   ],
   "summary": "CodeMender fixes rather than finds: 72 security patches upstreamed over six months, each human-reviewed, with the model inside the harness moving from Gemini Deep Think to Gemini 3.5 Flash Cyber and then 3.8 Flash Cyber.",
   "confidence": "SINGLE",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0069/"
  },
  {
   "id": "aifv-0030",
   "cve": "CVE-2026-25242",
   "ghsa": "GHSA-fc3h-92p8-h36f",
   "title": "Gogs unauthenticated file upload, disclosed by OpenAI Security Research",
   "project": "Gogs",
   "component": "file upload",
   "bugClass": "unauthenticated file upload",
   "finder": "OpenAI Aardvark",
   "finderOrg": "OpenAI Security Research",
   "autonomy": "agentic security researcher; disclosures filed by OpenAI",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "GHSA-fc3h-92p8-h36f: \"Date: Aug 5, 2025 Discoverer: OpenAI Security Research\"; the CVE credits array is empty",
   "assigner": "GitHub",
   "date": "2026-02-19",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 6.9,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/25xxx/CVE-2026-25242.json"
    },
    {
     "label": "GitHub advisory GHSA-fc3h-92p8-h36f",
     "url": "https://github.com/advisories/GHSA-fc3h-92p8-h36f"
    }
   ],
   "summary": "An unauthenticated file upload in Gogs, advisory published 17 February 2026 and CVE record 19 February, whose disclosure header dates the discovery to 5 August 2025, three months before OpenAI announced Aardvark.",
   "confidence": "CONFIRMED",
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0030/"
  },
  {
   "id": "aifv-0029",
   "cve": "CVE-2025-64175",
   "ghsa": "GHSA-p6x6-9mx6-26wj",
   "title": "Gogs two-factor bypass via recovery code, disclosed by OpenAI Security Research",
   "project": "Gogs",
   "component": "two-factor authentication",
   "bugClass": "2FA bypass via recovery code",
   "finder": "OpenAI Aardvark",
   "finderOrg": "OpenAI Security Research",
   "autonomy": "agentic security researcher; disclosures filed by OpenAI",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "GHSA-p6x6-9mx6-26wj names OpenAI Security Research and outbounddisclosures@openai.com; the CVE credits array is empty",
   "assigner": "GitHub",
   "date": "2026-02-06",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 7.7,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/64xxx/CVE-2025-64175.json"
    },
    {
     "label": "GitHub advisory GHSA-p6x6-9mx6-26wj",
     "url": "https://github.com/advisories/GHSA-p6x6-9mx6-26wj"
    }
   ],
   "summary": "A two-factor bypass in Gogs published 6 February 2026 with GitHub as CNA, whose advisory text names OpenAI Security Research as the discloser.",
   "confidence": "CONFIRMED",
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0029/"
  },
  {
   "id": "aifv-0062",
   "cve": null,
   "title": "AISLE claims more than 225 CVEs across OpenSSL, the Linux kernel, curl, Apache, Mozilla, Redis and Elastic",
   "project": "OpenSSL, Linux kernel, curl, Apache, Mozilla, Redis, Elastic",
   "component": null,
   "bugClass": "aggregate: 225-plus CVEs claimed",
   "finder": "AISLE",
   "finderOrg": "Aisle Research",
   "autonomy": "autonomous system per the company",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "company claim; four OpenSSL records confirmed at the CVE record are their own rows here",
   "assigner": null,
   "date": "2026-01-27",
   "dateBasis": "the coordinated OpenSSL release AISLE claims in full",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "OpenSSL security advisory, 27 January 2026",
     "url": "https://openssl-library.org/news/secadv/20260127.txt"
    }
   ],
   "summary": "AISLE says it holds all twelve CVEs in the OpenSSL release of 27 January 2026, credit on 13 of 14 OpenSSL CVEs assigned in 2025, three of the six CVEs fixed in curl 8.18.0, and more than 225 CVEs in total. That last figure would make it the largest contributor here by an order of magnitude and rests on the company's own pages.",
   "confidence": "SINGLE",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0062/"
  },
  {
   "id": "aifv-0042",
   "cve": "CVE-2026-22795",
   "title": "OpenSSL invalid or NULL pointer dereference in PKCS#12 ASN1_TYPE validation, credited to Aisle Research",
   "project": "OpenSSL",
   "component": "PKCS#12 ASN1_TYPE validation",
   "bugClass": "invalid or NULL pointer dereference",
   "finder": "AISLE",
   "finderOrg": "Aisle Research",
   "autonomy": "autonomous system per the company; OpenSSL credits named Aisle Research staff",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "reporter: Luigino Camastra (Aisle Research); remediation developer: Bob Beck",
   "assigner": "openssl",
   "date": "2026-01-27",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "OpenSSL severity policy",
    "score": null,
    "rating": "Low"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/22xxx/CVE-2026-22795.json"
    },
    {
     "label": "OpenSSL security advisory, 27 January 2026",
     "url": "https://openssl-library.org/news/secadv/20260127.txt"
    }
   ],
   "summary": "One of four OpenSSL records of 27 January 2026 whose credits name people at Aisle Research; the claim that an autonomous system found them is the company's. AISLE says it holds all twelve CVEs in that coordinated release, a figure this desk has not confirmed at the record.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0042/"
  },
  {
   "id": "aifv-0041",
   "cve": "CVE-2025-69421",
   "title": "OpenSSL NULL pointer dereference in PKCS12_item_decrypt_d2i_ex(), credited to Aisle Research",
   "project": "OpenSSL",
   "component": "PKCS12_item_decrypt_d2i_ex()",
   "bugClass": "NULL pointer dereference",
   "finder": "AISLE",
   "finderOrg": "Aisle Research",
   "autonomy": "autonomous system per the company; OpenSSL credits named Aisle Research staff",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "reporter and remediation developer: Luigino Camastra (Aisle Research)",
   "assigner": "openssl",
   "date": "2026-01-27",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "OpenSSL severity policy",
    "score": null,
    "rating": "Low"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/69xxx/CVE-2025-69421.json"
    },
    {
     "label": "OpenSSL security advisory, 27 January 2026",
     "url": "https://openssl-library.org/news/secadv/20260127.txt"
    }
   ],
   "summary": "One of four OpenSSL records of 27 January 2026 whose credits name people at Aisle Research; the claim that an autonomous system found them is the company's. AISLE says it holds all twelve CVEs in that coordinated release, a figure this desk has not confirmed at the record.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0041/"
  },
  {
   "id": "aifv-0040",
   "cve": "CVE-2025-11187",
   "title": "OpenSSL stack overflow, invalid or NULL pointer in PKCS#12 PBMAC1 MAC verification, credited to Aisle Research",
   "project": "OpenSSL",
   "component": "PKCS#12 PBMAC1 MAC verification",
   "bugClass": "stack overflow, invalid or NULL pointer",
   "finder": "AISLE",
   "finderOrg": "Aisle Research",
   "autonomy": "autonomous system per the company; OpenSSL credits named Aisle Research staff",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "reporters: Stanislav Fort (Aisle Research), Petr Šimeček (Aisle Research), Hamza (Metadust); remediation developer: Tomáš Mráz",
   "assigner": "openssl",
   "date": "2026-01-27",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "OpenSSL severity policy",
    "score": null,
    "rating": "Moderate"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/11xxx/CVE-2025-11187.json"
    },
    {
     "label": "OpenSSL security advisory, 27 January 2026",
     "url": "https://openssl-library.org/news/secadv/20260127.txt"
    }
   ],
   "summary": "One of four OpenSSL records of 27 January 2026 whose credits name people at Aisle Research; the claim that an autonomous system found them is the company's. AISLE says it holds all twelve CVEs in that coordinated release, a figure this desk has not confirmed at the record.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0040/"
  },
  {
   "id": "aifv-0039",
   "cve": "CVE-2025-15467",
   "title": "OpenSSL stack buffer overflow, AEAD parameters in CMS (Auth)EnvelopedData parsing, credited to Aisle Research",
   "project": "OpenSSL",
   "component": "CMS (Auth)EnvelopedData parsing",
   "bugClass": "stack buffer overflow, AEAD parameters",
   "finder": "AISLE",
   "finderOrg": "Aisle Research",
   "autonomy": "autonomous system per the company; OpenSSL credits named Aisle Research staff",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "reporter: Stanislav Fort (Aisle Research); remediation developer: Igor Ustinov",
   "assigner": "openssl",
   "date": "2026-01-27",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "OpenSSL severity policy",
    "score": null,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/15xxx/CVE-2025-15467.json"
    },
    {
     "label": "OpenSSL security advisory, 27 January 2026",
     "url": "https://openssl-library.org/news/secadv/20260127.txt"
    }
   ],
   "summary": "One of four OpenSSL records of 27 January 2026 whose credits name people at Aisle Research; the claim that an autonomous system found them is the company's. AISLE says it holds all twelve CVEs in that coordinated release, a figure this desk has not confirmed at the record.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0039/"
  },
  {
   "id": "aifv-0023",
   "cve": "CVE-2025-43434",
   "title": "Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by Apple",
   "project": "Safari",
   "component": "WebKit",
   "bugClass": "memory safety issue (class per Apple advisory)",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "\"Google Big Sleep\" on support.apple.com/en-us/125640; the CVE record carries no credits array",
   "assigner": "Apple",
   "date": "2025-11-04",
   "dateBasis": "datePublished",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null,
    "note": "Apple publishes no CVSS"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/43xxx/CVE-2025-43434.json"
    },
    {
     "label": "Apple, About the security content of Safari 26.1",
     "url": "https://support.apple.com/en-us/125640"
    }
   ],
   "summary": "One of five Safari records Apple published on 4 November 2025 and fixed in Safari 26.1, each crediting Google Big Sleep on the Safari 26.1 security page. The sixth record of the same date, CVE-2025-43432, credits Hossein Lotfi of the Trend Micro Zero Day Initiative and stays out of this block.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0023/"
  },
  {
   "id": "aifv-0022",
   "cve": "CVE-2025-43433",
   "title": "Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by Apple",
   "project": "Safari",
   "component": "WebKit",
   "bugClass": "memory safety issue (class per Apple advisory)",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "\"Google Big Sleep\" on support.apple.com/en-us/125640; the CVE record carries no credits array",
   "assigner": "Apple",
   "date": "2025-11-04",
   "dateBasis": "datePublished",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null,
    "note": "Apple publishes no CVSS"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/43xxx/CVE-2025-43433.json"
    },
    {
     "label": "Apple, About the security content of Safari 26.1",
     "url": "https://support.apple.com/en-us/125640"
    }
   ],
   "summary": "One of five Safari records Apple published on 4 November 2025 and fixed in Safari 26.1, each crediting Google Big Sleep on the Safari 26.1 security page. The sixth record of the same date, CVE-2025-43432, credits Hossein Lotfi of the Trend Micro Zero Day Initiative and stays out of this block.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0022/"
  },
  {
   "id": "aifv-0021",
   "cve": "CVE-2025-43431",
   "title": "Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by Apple",
   "project": "Safari",
   "component": "WebKit",
   "bugClass": "memory safety issue (class per Apple advisory)",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "\"Google Big Sleep\" on support.apple.com/en-us/125640; the CVE record carries no credits array",
   "assigner": "Apple",
   "date": "2025-11-04",
   "dateBasis": "datePublished",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null,
    "note": "Apple publishes no CVSS"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/43xxx/CVE-2025-43431.json"
    },
    {
     "label": "Apple, About the security content of Safari 26.1",
     "url": "https://support.apple.com/en-us/125640"
    }
   ],
   "summary": "One of five Safari records Apple published on 4 November 2025 and fixed in Safari 26.1, each crediting Google Big Sleep on the Safari 26.1 security page. The sixth record of the same date, CVE-2025-43432, credits Hossein Lotfi of the Trend Micro Zero Day Initiative and stays out of this block.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0021/"
  },
  {
   "id": "aifv-0020",
   "cve": "CVE-2025-43430",
   "title": "Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by Apple",
   "project": "Safari",
   "component": "WebKit",
   "bugClass": "memory safety issue (class per Apple advisory)",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "\"Google Big Sleep\" on support.apple.com/en-us/125640; the CVE record carries no credits array",
   "assigner": "Apple",
   "date": "2025-11-04",
   "dateBasis": "datePublished",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null,
    "note": "Apple publishes no CVSS"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/43xxx/CVE-2025-43430.json"
    },
    {
     "label": "Apple, About the security content of Safari 26.1",
     "url": "https://support.apple.com/en-us/125640"
    }
   ],
   "summary": "One of five Safari records Apple published on 4 November 2025 and fixed in Safari 26.1, each crediting Google Big Sleep on the Safari 26.1 security page. The sixth record of the same date, CVE-2025-43432, credits Hossein Lotfi of the Trend Micro Zero Day Initiative and stays out of this block.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0020/"
  },
  {
   "id": "aifv-0019",
   "cve": "CVE-2025-43429",
   "title": "Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by Apple",
   "project": "Safari",
   "component": "WebKit",
   "bugClass": "memory safety issue (class per Apple advisory)",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "\"Google Big Sleep\" on support.apple.com/en-us/125640; the CVE record carries no credits array",
   "assigner": "Apple",
   "date": "2025-11-04",
   "dateBasis": "datePublished",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null,
    "note": "Apple publishes no CVSS"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/43xxx/CVE-2025-43429.json"
    },
    {
     "label": "Apple, About the security content of Safari 26.1",
     "url": "https://support.apple.com/en-us/125640"
    }
   ],
   "summary": "One of five Safari records Apple published on 4 November 2025 and fixed in Safari 26.1, each crediting Google Big Sleep on the Safari 26.1 security page. The sixth record of the same date, CVE-2025-43432, credits Hossein Lotfi of the Trend Micro Zero Day Initiative and stays out of this block.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0019/"
  },
  {
   "id": "aifv-0017",
   "cve": "CVE-2025-11731",
   "title": "libxslt type confusion in exsltFuncResultComp, found by Google Big Sleep",
   "project": "libxslt",
   "component": "exsltFuncResultComp",
   "bugClass": "type confusion",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "Red Hat would like to thank Google Big Sleep for reporting this issue.",
   "assigner": "Red Hat",
   "date": "2025-10-14",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 3.1,
    "rating": "Low"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/11xxx/CVE-2025-11731.json"
    }
   ],
   "summary": "A type confusion in libxslt before 1.1.44, assigned by Red Hat with a Big Sleep acknowledgement in the credits, one of two 2026-era Big Sleep records that reach the corpus through a downstream distributor rather than Google as CNA.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0017/"
  },
  {
   "id": "aifv-0063",
   "cve": null,
   "title": "curl merged about 50 fixes from Joshua Rogers' AI-assisted scanner run",
   "project": "curl",
   "component": null,
   "bugClass": "aggregate: about 50 merged fixes, mostly correctness bugs, one or two security-relevant",
   "finder": "AI-assisted scanners (ZeroPath, Almanax, Corgea, Gecko, Amplify), run by Joshua Rogers",
   "finderOrg": "Joshua Rogers (independent)",
   "autonomy": "several tools run, every output read and filtered by the researcher before submission",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "Daniel Stenberg's posts of 21 September and 1 October 2025",
   "assigner": null,
   "date": "2025-10-01",
   "dateBasis": "Stenberg's post of 1 October 2025",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "Daniel Stenberg's blog",
     "url": "https://daniel.haxx.se/blog/"
    }
   ],
   "summary": "Between September and October 2025 Rogers sent curl a long list of issues found with a mix of AI-assisted scanners; Stenberg recorded 22 fixes landed by 21 September and roughly 50 merged by early October, the majority ordinary correctness bugs.",
   "confidence": "SINGLE",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0063/"
  },
  {
   "id": "aifv-0016",
   "cve": "CVE-2025-9086",
   "title": "curl out-of-bounds read in cookie path handling, found by Google Big Sleep",
   "project": "curl",
   "component": "cookie path",
   "bugClass": "out-of-bounds read",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"; remediation developer: Daniel Stenberg",
   "assigner": "curl",
   "date": "2025-09-12",
   "dateBasis": "datePublished",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null,
    "note": "the record carries no metrics"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "HackerOne (curl), report 3294999; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/9xxx/CVE-2025-9086.json"
    }
   ],
   "summary": "An out-of-bounds read for the cookie path in curl up to 8.15.0, assigned by curl with Big Sleep as finder and Daniel Stenberg as remediation developer. The record carries no datePublic and no CVSS; its third reference is HackerOne report 3294999.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0016/"
  },
  {
   "id": "aifv-0024",
   "cve": "CVE-2025-9478",
   "title": "Chrome ANGLE use-after-free, critical, reported by Google Big Sleep",
   "project": "Google Chrome",
   "component": "ANGLE",
   "bugClass": "use-after-free",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "Critical CVE-2025-9478: Use after free in ANGLE. Reported by Google Big Sleep on 2025-08-11",
   "assigner": "Chrome",
   "date": "2025-08-26",
   "dateBasis": "release note",
   "severity": {
    "scale": "Chromium severity",
    "score": null,
    "rating": "Critical"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/9xxx/CVE-2025-9478.json"
    },
    {
     "label": "Chrome Releases, Stable Channel Update, 26 August 2025",
     "url": "https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_26.html"
    }
   ],
   "summary": "A critical use-after-free in ANGLE fixed in Chrome 139.0.7258.154, credited to Google Big Sleep in the Stable Channel Update of 26 August 2025, reported to Chrome on 11 August 2025.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0024/"
  },
  {
   "id": "aifv-0008",
   "cve": "CVE-2025-59734",
   "title": "FFmpeg SANM process_ftch: use-after-free write, found by Google Big Sleep",
   "project": "FFmpeg",
   "component": "SANM process_ftch",
   "bugClass": "use-after-free write",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-08-20",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 8.7,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/59xxx/CVE-2025-59734.json"
    }
   ],
   "summary": "One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0008/"
  },
  {
   "id": "aifv-0025",
   "cve": "CVE-2025-9132",
   "title": "Chrome V8 out-of-bounds write, reported by Google Big Sleep",
   "project": "Google Chrome",
   "component": "V8",
   "bugClass": "out-of-bounds write",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "cna-advisory",
   "creditsVerbatim": "CVE-2025-9132: Out of bounds write in V8. Reported by Google Big Sleep on 2025-08-04",
   "assigner": "Chrome",
   "date": "2025-08-19",
   "dateBasis": "release note",
   "severity": {
    "scale": "Chromium severity",
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/9xxx/CVE-2025-9132.json"
    },
    {
     "label": "Chrome Releases, Stable Channel Update, 19 August 2025",
     "url": "https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_19.html"
    }
   ],
   "summary": "An out-of-bounds write in V8 fixed in Chrome 139.0.7258.138, credited to Google Big Sleep in the Stable Channel Update of 19 August 2025, reported to Chrome on 4 August 2025. Settled at the release note on 19 September 2026 after a sibling note had carried it as contested.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0025/"
  },
  {
   "id": "aifv-0059",
   "cve": null,
   "title": "AIxCC finalists surfaced 18 previously unknown real-world flaws and patched 11 of them",
   "project": "AIxCC challenge projects (open-source)",
   "component": null,
   "bugClass": "aggregate: 18 real-world flaws, 11 patched",
   "finder": "AIxCC finalist cyber reasoning systems",
   "finderOrg": "DARPA AI Cyber Challenge, seven finalist teams",
   "autonomy": "fully autonomous cyber reasoning systems in competition conditions",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "DARPA announcement, DEF CON 33",
   "assigner": null,
   "date": "2025-08-08",
   "dateBasis": "DEF CON 33 final, August 2025",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": true,
    "amountUsd": 8500000,
    "programme": "competition prizes: Team Atlanta $4m, Trail of Bits $3m, Theori $1.5m"
   },
   "links": [
    {
     "label": "Team Atlanta, Atlantis CRS repository",
     "url": "https://raw.githubusercontent.com/Team-Atlanta/aixcc-afc-atlantis/main/README.md"
    }
   ],
   "summary": "Seven finalist systems discovered 54 of the synthetic vulnerabilities planted in the challenge projects, patched 43 of those, and surfaced 18 real-world flaws of which 11 were patched, the rest routed to maintainers. The mapping from finding to CVE identifier is still open, so the 18 enter as one row.",
   "confidence": "SINGLE",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0059/"
  },
  {
   "id": "aifv-0007",
   "cve": "CVE-2025-59733",
   "title": "FFmpeg EXR dwa_uncompress: mixed channel pixel types, found by Google Big Sleep",
   "project": "FFmpeg",
   "component": "EXR dwa_uncompress",
   "bugClass": "mixed channel pixel types",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-08-04",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 8.7,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/59xxx/CVE-2025-59733.json"
    }
   ],
   "summary": "One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0007/"
  },
  {
   "id": "aifv-0006",
   "cve": "CVE-2025-59732",
   "title": "FFmpeg EXR dwa_uncompress: dimensions not divisible by 8, found by Google Big Sleep",
   "project": "FFmpeg",
   "component": "EXR dwa_uncompress",
   "bugClass": "dimensions not divisible by 8",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-08-04",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 8.7,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/59xxx/CVE-2025-59732.json"
    }
   ],
   "summary": "One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0006/"
  },
  {
   "id": "aifv-0005",
   "cve": "CVE-2025-59731",
   "title": "FFmpeg EXR dwa_uncompress: RLE raw length unchecked, found by Google Big Sleep",
   "project": "FFmpeg",
   "component": "EXR dwa_uncompress",
   "bugClass": "RLE raw length unchecked",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-08-04",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 6.9,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/59xxx/CVE-2025-59731.json"
    }
   ],
   "summary": "One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0005/"
  },
  {
   "id": "aifv-0004",
   "cve": "CVE-2025-59730",
   "title": "FFmpeg SANM old_codec48: heap overflow write, found by Google Big Sleep",
   "project": "FFmpeg",
   "component": "SANM old_codec48",
   "bugClass": "heap overflow write",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-27",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 5.7,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/59xxx/CVE-2025-59730.json"
    }
   ],
   "summary": "One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0004/"
  },
  {
   "id": "aifv-0015",
   "cve": "CVE-2025-62496",
   "title": "QuickJS js_bigint_from_string: integer overflow, found by Google Big Sleep",
   "project": "QuickJS",
   "component": "js_bigint_from_string",
   "bugClass": "integer overflow",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-24",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 7.1,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/62xxx/CVE-2025-62496.json"
    }
   ],
   "summary": "One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.",
   "details": null,
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0015/"
  },
  {
   "id": "aifv-0014",
   "cve": "CVE-2025-62495",
   "title": "QuickJS libregexp: bytecode size integer overflow, found by Google Big Sleep",
   "project": "QuickJS",
   "component": "libregexp",
   "bugClass": "bytecode size integer overflow",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-24",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 7.1,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/62xxx/CVE-2025-62495.json"
    }
   ],
   "summary": "One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.",
   "details": "The record title duplicates CVE-2025-62494, \"Type confusion in string addition in QuickJS\", while its description is the libregexp bytecode integer overflow; the description is right and the upstream title is the duplicate.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0014/"
  },
  {
   "id": "aifv-0013",
   "cve": "CVE-2025-62494",
   "title": "QuickJS string addition: type confusion, found by Google Big Sleep",
   "project": "QuickJS",
   "component": "string addition",
   "bugClass": "type confusion",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-24",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 7.1,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/62xxx/CVE-2025-62494.json"
    }
   ],
   "summary": "One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.",
   "details": null,
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0013/"
  },
  {
   "id": "aifv-0012",
   "cve": "CVE-2025-62493",
   "title": "QuickJS js_bigint_to_string1: out-of-bounds read, found by Google Big Sleep",
   "project": "QuickJS",
   "component": "js_bigint_to_string1",
   "bugClass": "out-of-bounds read",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-24",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 5.9,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/62xxx/CVE-2025-62493.json"
    }
   ],
   "summary": "One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.",
   "details": null,
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0012/"
  },
  {
   "id": "aifv-0011",
   "cve": "CVE-2025-62492",
   "title": "QuickJS js_typed_array_indexOf: out-of-bounds read via float precision, found by Google Big Sleep",
   "project": "QuickJS",
   "component": "js_typed_array_indexOf",
   "bugClass": "out-of-bounds read via float precision",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-24",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 5.9,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/62xxx/CVE-2025-62492.json"
    }
   ],
   "summary": "One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.",
   "details": null,
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0011/"
  },
  {
   "id": "aifv-0010",
   "cve": "CVE-2025-62491",
   "title": "QuickJS js_std_promise_rejection_check: use-after-free, found by Google Big Sleep",
   "project": "QuickJS",
   "component": "js_std_promise_rejection_check",
   "bugClass": "use-after-free",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-24",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 8.8,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/62xxx/CVE-2025-62491.json"
    }
   ],
   "summary": "One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.",
   "details": null,
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0010/"
  },
  {
   "id": "aifv-0009",
   "cve": "CVE-2025-62490",
   "title": "QuickJS js_print_object: use-after-free, found by Google Big Sleep",
   "project": "QuickJS",
   "component": "js_print_object",
   "bugClass": "use-after-free",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-24",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 8.8,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/62xxx/CVE-2025-62490.json"
    }
   ],
   "summary": "One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.",
   "details": null,
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0009/"
  },
  {
   "id": "aifv-0003",
   "cve": "CVE-2025-59729",
   "title": "FFmpeg DHAV get_duration: heap overflow read, found by Google Big Sleep",
   "project": "FFmpeg",
   "component": "DHAV get_duration",
   "bugClass": "heap overflow read",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-21",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 5.7,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/59xxx/CVE-2025-59729.json"
    }
   ],
   "summary": "One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0003/"
  },
  {
   "id": "aifv-0002",
   "cve": "CVE-2025-59728",
   "title": "FFmpeg MPEG-DASH resolve_content_path: heap overflow write, found by Google Big Sleep",
   "project": "FFmpeg",
   "component": "MPEG-DASH resolve_content_path",
   "bugClass": "heap overflow write",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google Big Sleep\"",
   "assigner": "Google",
   "date": "2025-07-21",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 8.7,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/59xxx/CVE-2025-59728.json"
    }
   ],
   "summary": "One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0002/"
  },
  {
   "id": "aifv-0028",
   "cve": "CVE-2025-32990",
   "title": "GnuTLS heap buffer overflow in certtool, attributed to OpenAI Aardvark",
   "project": "GnuTLS",
   "component": "certtool",
   "bugClass": "heap buffer overflow",
   "finder": "OpenAI Aardvark",
   "finderOrg": "OpenAI Security Research",
   "autonomy": "agentic security researcher; disclosures filed by OpenAI",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in OpenAI announcements",
   "assigner": "Red Hat",
   "date": "2025-07-10",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 6.5,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/32xxx/CVE-2025-32990.json"
    },
    {
     "label": "OpenAI, Introducing Aardvark",
     "url": "https://openai.com/index/introducing-aardvark/"
    }
   ],
   "summary": "One of three GnuTLS records published by Red Hat on 10 July 2025 that OpenAI attributes to Aardvark, its agentic security researcher announced in October 2025 and folded into Codex as Codex Security on 6 March 2026. The record itself carries an empty credits array.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0028/"
  },
  {
   "id": "aifv-0027",
   "cve": "CVE-2025-32989",
   "title": "GnuTLS heap buffer overread in SCT extension parsing, attributed to OpenAI Aardvark",
   "project": "GnuTLS",
   "component": "SCT extension parsing",
   "bugClass": "heap buffer overread",
   "finder": "OpenAI Aardvark",
   "finderOrg": "OpenAI Security Research",
   "autonomy": "agentic security researcher; disclosures filed by OpenAI",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in OpenAI announcements",
   "assigner": "Red Hat",
   "date": "2025-07-10",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 5.3,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/32xxx/CVE-2025-32989.json"
    },
    {
     "label": "OpenAI, Introducing Aardvark",
     "url": "https://openai.com/index/introducing-aardvark/"
    }
   ],
   "summary": "One of three GnuTLS records published by Red Hat on 10 July 2025 that OpenAI attributes to Aardvark, its agentic security researcher announced in October 2025 and folded into Codex as Codex Security on 6 March 2026. The record itself carries an empty credits array.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0027/"
  },
  {
   "id": "aifv-0026",
   "cve": "CVE-2025-32988",
   "title": "GnuTLS double free in otherName SAN export, attributed to OpenAI Aardvark",
   "project": "GnuTLS",
   "component": "otherName SAN export",
   "bugClass": "double free",
   "finder": "OpenAI Aardvark",
   "finderOrg": "OpenAI Security Research",
   "autonomy": "agentic security researcher; disclosures filed by OpenAI",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in OpenAI announcements",
   "assigner": "Red Hat",
   "date": "2025-07-10",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 6.5,
    "rating": "Medium"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/32xxx/CVE-2025-32988.json"
    },
    {
     "label": "OpenAI, Introducing Aardvark",
     "url": "https://openai.com/index/introducing-aardvark/"
    }
   ],
   "summary": "One of three GnuTLS records published by Red Hat on 10 July 2025 that OpenAI attributes to Aardvark, its agentic security researcher announced in October 2025 and folded into Codex as Codex Security on 6 March 2026. The record itself carries an empty credits array.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0026/"
  },
  {
   "id": "aifv-0001",
   "cve": "CVE-2025-6965",
   "title": "SQLite integer truncation found with Google Big Sleep, cut off before exploitation",
   "project": "SQLite",
   "component": "aggregate term handling",
   "bugClass": "integer truncation, aggregate terms exceed columns",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent assisting a named human researcher",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "Vlad Stolyarov of Google's Threat Analysis Group, with assistance from Google Big Sleep",
   "assigner": "Google",
   "date": "2025-06-27",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 7.2,
    "rating": "High"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/6xxx/CVE-2025-6965.json"
    },
    {
     "label": "Google Cloud CISO Perspectives on Big Sleep",
     "url": "https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-our-big-sleep-agent-makes-big-leap"
    }
   ],
   "summary": "An integer truncation in SQLite before 3.50.2 where the number of aggregate terms could exceed the columns available, published by Google as CNA on 15 July 2025. Google says the flaw was known only to threat actors and about to be used, and that Big Sleep with Threat Intelligence Group input identified it first.",
   "details": "The credit names a human researcher with assistance from the agent, so the flagship result is human-plus-agent while the routine Big Sleep records name the agent alone.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0001/"
  },
  {
   "id": "aifv-0058",
   "cve": null,
   "title": "XBOW submitted close to 1,060 reports to HackerOne programmes and topped the US leaderboard",
   "project": "HackerOne programmes (various)",
   "component": null,
   "bugClass": "aggregate: 54 critical, 242 high, 524 medium, 65 low",
   "finder": "XBOW",
   "finderOrg": "XBOW",
   "autonomy": "autonomous pentester with human review before submission",
   "evidenceTier": "aggregate",
   "creditsVerbatim": "XBOW's own post: \"XBOW submitted nearly 1,060 vulnerabilities\"",
   "assigner": null,
   "date": "2025-06-24",
   "dateBasis": "XBOW post, 24 June 2025",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "HackerOne; XBOW published no cash total and said bounty income ran below the compute cost of the runs"
   },
   "links": [
    {
     "label": "XBOW, how XBOW ranked number one",
     "url": "https://xbow.com/blog/top-1-how-xbow-did-it"
    }
   ],
   "summary": "Roughly 1,060 reports in about 90 days to June 2025: 130 resolved, 303 triaged, 208 duplicate, 209 informative and 36 not applicable, per XBOW's own post. The individual reports are largely undisclosed, so the campaign enters as one aggregate row.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0058/"
  },
  {
   "id": "aifv-0043",
   "cve": "CVE-2025-37899",
   "title": "Linux ksmbd use-after-free in session logoff, found with OpenAI o3 by Sean Heelan",
   "project": "Linux kernel",
   "component": "ksmbd, smb2_session_logoff",
   "bugClass": "use-after-free",
   "finder": "OpenAI o3, run by Sean Heelan",
   "finderOrg": "Sean Heelan (independent)",
   "model": "o3",
   "autonomy": "model given about 12,000 lines of SMB handlers and prompted for use-after-free; the researcher validated the result",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty (normal for Linux CNA records); attribution in the researcher's own account",
   "assigner": "Linux",
   "date": "2025-05-20",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 8.8,
    "rating": "High",
    "vector": "AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/37xxx/CVE-2025-37899.json"
    },
    {
     "label": "Sean Heelan, how I used o3 to find CVE-2025-37899",
     "url": "https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/"
    }
   ],
   "summary": "\"ksmbd: fix use-after-free in session logoff\", published 20 May 2025. Heelan's account is that o3 surfaced the concurrency flaw in smb2_session_logoff when given the SMB command handlers and asked to look for use-after-free.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0043/"
  },
  {
   "id": "aifv-0046",
   "cve": "CVE-2025-0133",
   "title": "PAN-OS GlobalProtect reflected cross-site scripting, found by XBOW",
   "project": "Palo Alto Networks PAN-OS",
   "component": "GlobalProtect gateway and portal",
   "bugClass": "reflected cross-site scripting",
   "finder": "XBOW",
   "finderOrg": "XBOW",
   "autonomy": "autonomous pentester with human review before submission",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"XBOW\"",
   "assigner": "palo_alto",
   "date": "2025-05-14",
   "dateBasis": "datePublic",
   "severity": {
    "scale": "CVSS 4.0",
    "score": 2.7,
    "rating": "Low",
    "note": "1.2 without Clientless VPN",
    "vector": "AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/U:Amber"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "HackerOne; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/0xxx/CVE-2025-0133.json"
    },
    {
     "label": "Palo Alto Networks security advisory",
     "url": "https://security.paloaltonetworks.com/CVE-2025-0133"
    }
   ],
   "summary": "A reflected cross-site scripting flaw in the GlobalProtect gateway and portal, assigned by Palo Alto Networks with XBOW named as finder in the credits array. The record scores it 1.2 and 2.7 Low on CVSS 4.0, against the 2.0 and 5.5 in circulation.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0046/"
  },
  {
   "id": "aifv-0044",
   "cve": "CVE-2025-37778",
   "title": "Linux ksmbd dangling pointer in krb_authenticate, the benchmark bug Sean Heelan ran o3 against",
   "project": "Linux kernel",
   "component": "ksmbd, krb_authenticate",
   "bugClass": "dangling pointer",
   "finder": "OpenAI o3, run by Sean Heelan",
   "finderOrg": "Sean Heelan (independent)",
   "model": "o3",
   "autonomy": "a known bug used as the benchmark for the o3 run; the model rediscovered it",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in the researcher's own account",
   "assigner": "Linux",
   "date": "2025-05-01",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 9.8,
    "rating": "Critical"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/37xxx/CVE-2025-37778.json"
    },
    {
     "label": "Sean Heelan, how I used o3 to find CVE-2025-37899",
     "url": "https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/"
    }
   ],
   "summary": "\"ksmbd: Fix dangling pointer in krb_authenticate\", published 1 May 2025. The row is the control inside Heelan's experiment: a bug already found by a person, which o3 rediscovered before it went on to CVE-2025-37899.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0044/"
  },
  {
   "id": "aifv-0036",
   "cve": "CVE-2024-9309",
   "title": "LLaVA server-side request forgery at POST /worker_generate_stream, found by Vulnhuntr",
   "project": "haotian-liu/LLaVA",
   "component": null,
   "bugClass": "server-side request forgery at POST /worker_generate_stream",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in the Vulnhuntr README",
   "assigner": "@huntr_ai",
   "date": "2025-03-20",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 9.3,
    "rating": "Critical"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/9xxx/CVE-2024-9309.json"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "A server-side request forgery at POST /worker_generate_stream in haotian-liu/LLaVA, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under \"World's first autonomous AI-discovered 0day vulnerabilities\". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0036/"
  },
  {
   "id": "aifv-0034",
   "cve": "CVE-2024-10044",
   "title": "FastChat server-side request forgery at POST /worker_generate_stream, found by Vulnhuntr",
   "project": "lm-sys/FastChat",
   "component": null,
   "bugClass": "server-side request forgery at POST /worker_generate_stream",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in the Vulnhuntr README",
   "assigner": "@huntr_ai",
   "date": "2024-12-30",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 9.3,
    "rating": "Critical"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/10xxx/CVE-2024-10044.json"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "A server-side request forgery at POST /worker_generate_stream in lm-sys/FastChat, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under \"World's first autonomous AI-discovered 0day vulnerabilities\". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0034/"
  },
  {
   "id": "aifv-0057",
   "cve": null,
   "title": "SQLite stack buffer underflow in seriesBestIndex, the first public Big Sleep find, fixed before release",
   "project": "SQLite",
   "component": "seriesBestIndex",
   "bugClass": "stack buffer underflow, negative index write",
   "finder": "Google Big Sleep",
   "finderOrg": "Google DeepMind and Project Zero",
   "autonomy": "agent finds and reproduces; a human expert reviews before reporting",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "no CVE: the project fixed it the same day, before release",
   "assigner": null,
   "date": "2024-11-01",
   "dateBasis": "Project Zero announcement, 1 November 2024",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "Google Project Zero, From Naptime to Big Sleep",
     "url": "https://projectzero.google/2024/10/from-naptime-to-big-sleep.html"
    }
   ],
   "summary": "Google reported a write into a stack buffer with a negative index when a query carried a constraint on the rowid column; the project fixed it the same day and it never shipped. Google calls it \"the first public example of an AI agent finding a previously unknown exploitable memory-safety issue in widely used real-world software\".",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0057/"
  },
  {
   "id": "aifv-0035",
   "cve": "CVE-2024-10131",
   "title": "ragflow remote code execution in add_llm via llm_factory, found by Vulnhuntr",
   "project": "infiniflow/ragflow",
   "component": null,
   "bugClass": "remote code execution in add_llm via llm_factory",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in the Vulnhuntr README",
   "assigner": "@huntr_ai",
   "date": "2024-10-19",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 8.8,
    "rating": "High"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/10xxx/CVE-2024-10131.json"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "A remote code execution in add_llm via llm_factory in infiniflow/ragflow, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under \"World's first autonomous AI-discovered 0day vulnerabilities\". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0035/"
  },
  {
   "id": "aifv-0065",
   "cve": null,
   "title": "Langflow insecure direct object reference, found by Vulnhuntr, identifier redacted",
   "project": "Langflow",
   "component": null,
   "bugClass": "insecure direct object reference",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "listed in the Vulnhuntr README with the identifier redacted",
   "assigner": null,
   "date": "2024-10-17",
   "dateBasis": "Vulnhuntr README publication window",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "The second of two Langflow entries the Vulnhuntr README lists with the identifier redacted.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0065/"
  },
  {
   "id": "aifv-0064",
   "cve": null,
   "title": "Langflow remote code execution, found by Vulnhuntr, identifier redacted",
   "project": "Langflow",
   "component": null,
   "bugClass": "remote code execution",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "listed in the Vulnhuntr README with the identifier redacted",
   "assigner": null,
   "date": "2024-10-17",
   "dateBasis": "Vulnhuntr README publication window",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "One of two Langflow entries the Vulnhuntr README lists with the identifier redacted.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0064/"
  },
  {
   "id": "aifv-0038",
   "cve": null,
   "title": "letta arbitrary file overwrite, found by Vulnhuntr and fixed as a pull request",
   "project": "letta-ai/letta",
   "component": null,
   "bugClass": "arbitrary file overwrite",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "no CVE; the fix landed as a pull request named in the Vulnhuntr README",
   "assigner": null,
   "date": "2024-10-17",
   "dateBasis": "Vulnhuntr README publication window; the pull request carries its own date",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "Pull request 2067",
     "url": "https://github.com/letta-ai/letta/pull/2067"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "An arbitrary file overwrite in letta-ai/letta fixed as pull request 2067, one of two Vulnhuntr finds that landed as a patch rather than a CVE.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0038/"
  },
  {
   "id": "aifv-0037",
   "cve": null,
   "title": "gpt-researcher arbitrary file overwrite, found by Vulnhuntr and fixed as a pull request",
   "project": "assafelovic/gpt-researcher",
   "component": null,
   "bugClass": "arbitrary file overwrite",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "no CVE; the fix landed as a pull request named in the Vulnhuntr README",
   "assigner": null,
   "date": "2024-10-17",
   "dateBasis": "Vulnhuntr README publication window; the pull request carries its own date",
   "severity": {
    "scale": null,
    "score": null,
    "rating": null
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "Pull request 935",
     "url": "https://github.com/assafelovic/gpt-researcher/pull/935"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "An arbitrary file overwrite in assafelovic/gpt-researcher fixed as pull request 935, one of two Vulnhuntr finds that landed as a patch rather than a CVE.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0037/"
  },
  {
   "id": "aifv-0033",
   "cve": "CVE-2024-10099",
   "title": "ComfyUI stored cross-site scripting via /api/upload/image, found by Vulnhuntr",
   "project": "comfyanonymous/ComfyUI",
   "component": null,
   "bugClass": "stored cross-site scripting via /api/upload/image",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in the Vulnhuntr README",
   "assigner": "@huntr_ai",
   "date": "2024-10-17",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 6.1,
    "rating": "Medium"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/10xxx/CVE-2024-10099.json"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "A stored cross-site scripting via /api/upload/image in comfyanonymous/ComfyUI, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under \"World's first autonomous AI-discovered 0day vulnerabilities\". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0033/"
  },
  {
   "id": "aifv-0032",
   "cve": "CVE-2024-10101",
   "title": "gpt_academic stored cross-site scripting at /file, found by Vulnhuntr",
   "project": "binary-husky/gpt_academic",
   "component": null,
   "bugClass": "stored cross-site scripting at /file",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in the Vulnhuntr README",
   "assigner": "@huntr_ai",
   "date": "2024-10-17",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 5.4,
    "rating": "Medium"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/10xxx/CVE-2024-10101.json"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "A stored cross-site scripting at /file in binary-husky/gpt_academic, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under \"World's first autonomous AI-discovered 0day vulnerabilities\". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0032/"
  },
  {
   "id": "aifv-0031",
   "cve": "CVE-2024-10100",
   "title": "gpt_academic path traversal via URL-encoded file parameter, found by Vulnhuntr",
   "project": "binary-husky/gpt_academic",
   "component": null,
   "bugClass": "path traversal via URL-encoded file parameter",
   "finder": "Vulnhuntr",
   "finderOrg": "Protect AI",
   "autonomy": "LLM with Jedi static parsing, Python only; findings routed through huntr",
   "evidenceTier": "external-claim",
   "creditsVerbatim": "credits array empty; attribution in the Vulnhuntr README",
   "assigner": "@huntr_ai",
   "date": "2024-10-17",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "CVSS 3.1",
    "score": 6.5,
    "rating": "Medium"
   },
   "bounty": {
    "paid": null,
    "amountUsd": null,
    "programme": "huntr.com; amount unpublished"
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/10xxx/CVE-2024-10100.json"
    },
    {
     "label": "Vulnhuntr README",
     "url": "https://raw.githubusercontent.com/protectai/vulnhuntr/main/README.md"
    }
   ],
   "summary": "A path traversal via URL-encoded file parameter in binary-husky/gpt_academic, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under \"World's first autonomous AI-discovered 0day vulnerabilities\". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0031/"
  },
  {
   "id": "aifv-0045",
   "cve": "CVE-2024-9143",
   "title": "OpenSSL out-of-bounds memory access from invalid GF(2^m) parameters, found by a Google OSS-Fuzz-Gen harness",
   "project": "OpenSSL",
   "component": "low-level GF(2^m) elliptic curve parameters",
   "bugClass": "out-of-bounds memory access",
   "finder": "Google OSS-Fuzz-Gen",
   "finderOrg": "Google Open Source Security",
   "autonomy": "LLM-generated fuzz target run on OSS-Fuzz",
   "evidenceTier": "credits-array",
   "creditsVerbatim": "finder: \"Google OSS-Fuzz-Gen\"; remediation developer: Viktor Dukhovni",
   "assigner": "openssl",
   "date": "2024-10-16",
   "dateBasis": "datePublished",
   "severity": {
    "scale": "OpenSSL severity policy",
    "score": null,
    "rating": "Low"
   },
   "bounty": {
    "paid": false,
    "amountUsd": null,
    "programme": null
   },
   "links": [
    {
     "label": "CVE record, cvelistV5 mirror",
     "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/9xxx/CVE-2024-9143.json"
    },
    {
     "label": "google/oss-fuzz-gen README",
     "url": "https://raw.githubusercontent.com/google/oss-fuzz-gen/main/README.md"
    }
   ],
   "summary": "The cleanest attribution in the register: a CVE record naming an AI-generated fuzz harness as finder. It is the one entry with a CVE in the oss-fuzz-gen README's table of 30 bugs found by generated targets.",
   "confidence": "CONFIRMED",
   "ghsa": null,
   "model": null,
   "details": null,
   "url": "https://yfarmx.com/tools/ai-found-vulnerabilities/aifv-0045/"
  }
 ]
}