<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8" -->

---
title: AI Agents Are Disrupting Open Source Security Disclosure
description: AI agents can now turn fragmentary public clues about a vulnerability—like a PR title or a mailing list question—into working exploits within minutes,...
canonical: https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: AI Agents Are Disrupting Open Source Security Disclosure | daily.dev
og:description: AI agents can now turn fragmentary public clues about a vulnerability—like a PR title or a mailing list question—into working exploits within minutes,...
og:url: https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8
og:image: https://api.daily.dev/og/posts/SA7FQ5AU8.png
og:image:alt: AI Agents Are Disrupting Open Source Security Disclosure
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AI Agents Are Disrupting Open Source Security Disclosure

**[InfoQ](https://daily.dev/sources/infoq)** · 3 min read · 0 upvotes · 0 comments

## Summary

AI agents can now turn fragmentary public clues about a vulnerability—like a PR title or a mailing list question—into working exploits within minutes, undermining the traditional model of embargoing disclosures while patches are prepared. Anil Madhavapeddy, an OCaml maintainer, describes seeing exploit probes against a path-traversal bug minutes after opening his fix PR, and cites a study where a GPT-4 agent exploited 87% of vulnerabilities when given CVE descriptions versus 7% without. Chainguard's Adrian Mouat warns this may force projects to release before publishing source, undermining open source norms. Rclone maintainer Nick Craig-Wood reports receiving over 40 security disclosures in one month versus 20 in the project's first decade. Proposed mitigations include private coordination, faster continuous releases, and protocol-level controls like short-lived credentials and revocable capabilities; QEMU has already shortened its embargo windows in response.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoq.com/news/2026/10/open-source-ai-security>

## Questions this post answers

### Why did attackers start probing for a vulnerability minutes after a fix PR was opened on GitHub?

AI agents can monitor public signals like newly opened pull requests, mailing list questions, or odd commits on orphan branches, and independently reconstruct a working exploit from those clues alone. Anil Madhavapeddy, an OCaml maintainer, observed probes matching an exact bug pattern in his webserver logs minutes after opening a PR to fix a path-traversal vulnerability, before any public advisory existed.

_Maintainers racing exploit automation can follow fast-moving open source security practices on daily.dev._

### How much better are AI agents at exploiting vulnerabilities when given a CVE description versus no description?

A GPT-4 agent exploited 87% of vulnerabilities in a 15-vulnerability benchmark when given the corresponding CVE description, compared with only 7% success when given no description at all. This gap illustrates why even minimal public disclosure details can make embargoed vulnerabilities exploitable almost immediately.

_Developers evaluating AI exploit risk can track emerging security research like this on daily.dev._

### How has the volume of security disclosures changed for the rclone open source project?

Rclone maintainer Nick Craig-Wood reported receiving about 20 security disclosures through GitHub during the project's first 10 years, but over 40 disclosures arrived in a single month, a volume he says consumed a huge amount of his time even while using AI tools to triage and draft fixes.

_Maintainers overwhelmed by rising CVE volume can follow how others are coping on daily.dev._

## Similar posts on daily.dev

- [Just a rumour of a bug is enough to find a security exploit these days](https://daily.dev/posts/just-a-rumour-of-a-bug-is-enough-to-find-a-security-exploit-these-days-wzfcjbyf0) · Lobsters · 1 upvotes · 0 comments
- [AI is Breaking Two Vulnerability Cultures](https://daily.dev/posts/ai-is-breaking-two-vulnerability-cultures-icjk4gfak) · Hacker News · 1 upvotes · 0 comments
- [AI Is Exposing a Growing Blind Spot in Open Source Security](https://daily.dev/posts/ai-is-exposing-a-growing-blind-spot-in-open-source-security-g2xktncjz) · DevOps.com · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#ai-agents](https://daily.dev/tags/ai-agents), [#appsec](https://daily.dev/tags/appsec)

[View this post on daily.dev](https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"AI Agents Are Disrupting Open Source Security Disclosure","url":"https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8"},"datePublished":"2026-10-03T07:03:34.884Z","dateModified":"2026-10-03T07:03:56.074Z","description":"AI agents can now turn fragmentary public clues about a vulnerability—like a PR title or a mailing list question—into working exploits within minutes,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e67da5f0d002441802068335b8c0155a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e67da5f0d002441802068335b8c0155a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoQ","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoQ","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/afc3bced3e1e4b188dd9127017a60e0c","url":"https://daily.dev/sources/infoq"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,open-source,ai-agents,appsec","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoQ","item":"https://daily.dev/sources/infoq"},{"@type":"ListItem","position":3,"name":"AI Agents Are Disrupting Open Source Security Disclosure"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/ai-agents-are-disrupting-open-source-security-disclosure-sa7fq5au8#faq","mainEntity":[{"@type":"Question","name":"Why did attackers start probing for a vulnerability minutes after a fix PR was opened on GitHub?","acceptedAnswer":{"@type":"Answer","text":"AI agents can monitor public signals like newly opened pull requests, mailing list questions, or odd commits on orphan branches, and independently reconstruct a working exploit from those clues alone. Anil Madhavapeddy, an OCaml maintainer, observed probes matching an exact bug pattern in his webserver logs minutes after opening a PR to fix a path-traversal vulnerability, before any public advisory existed. Maintainers racing exploit automation can follow fast-moving open source security practices on daily.dev."}},{"@type":"Question","name":"How much better are AI agents at exploiting vulnerabilities when given a CVE description versus no description?","acceptedAnswer":{"@type":"Answer","text":"A GPT-4 agent exploited 87% of vulnerabilities in a 15-vulnerability benchmark when given the corresponding CVE description, compared with only 7% success when given no description at all. This gap illustrates why even minimal public disclosure details can make embargoed vulnerabilities exploitable almost immediately. Developers evaluating AI exploit risk can track emerging security research like this on daily.dev."}},{"@type":"Question","name":"How has the volume of security disclosures changed for the rclone open source project?","acceptedAnswer":{"@type":"Answer","text":"Rclone maintainer Nick Craig-Wood reported receiving about 20 security disclosures through GitHub during the project's first 10 years, but over 40 disclosures arrived in a single month, a volume he says consumed a huge amount of his time even while using AI tools to triage and draft fixes. Maintainers overwhelmed by rising CVE volume can follow how others are coping on daily.dev."}}]}
```

