VYPR
researchPublished Sep 2, 2026· 1 source

OWASP Launches OASIS AI Initiative to Fix Open Source Vulnerabilities at Scale

OWASP has launched the Open Automated Security Initiative for Software (OASIS) to leverage AI and human expertise for faster, more effective patching of open source vulnerabilities.

The Open Web Application Security Project (OWASP) has initiated the Open Automated Security Initiative for Software (OASIS), a new global effort aimed at bridging the gap between the discovery of vulnerabilities in open source code and their subsequent remediation. Announced on August 26, 2026, the OASIS initiative uniquely combines artificial intelligence with the critical oversight of human security professionals to generate and validate patch candidates.

This approach directly addresses a significant bottleneck in the open source ecosystem. With open source software forming the backbone of approximately 98% of commercial codebases, maintainers are often inundated with vulnerability reports from automated scanning tools. These tools frequently flag issues without providing actionable, ready-to-implement fixes, leaving maintainers overwhelmed and increasing the window of exposure. OASIS seeks to alleviate this burden by providing credible, vetted patches.

The OASIS process is structured in three key stages. First, AI-driven tooling automatically scans popular open source repositories, identifying emerging vulnerabilities and generating potential code fixes. Second, a dedicated community of application security practitioners and specialized agents meticulously reviews each AI-generated candidate. This human-in-the-loop validation ensures the correctness and safety of the proposed patches, drastically reducing review times to mere minutes and filtering out false positives.

Finally, once a patch candidate has been thoroughly vetted, it is submitted upstream to the relevant open source project maintainers. This ensures that maintainers receive production-grade remediation suggestions that they can more easily adapt to their specific codebases, rather than raw, unverified AI output. This model complements existing vulnerability scanning workflows by focusing on the crucial remediation phase.

Since its early sign-up period, OASIS has attracted hundreds of application security professionals from various industries. The initiative is supported by founding sponsors AppSecAI, Intigriti, and DryRun Security. Chris Holt, Strategic Engagement and Community Architect at Intigriti, highlighted the systemic risk posed by unremediated open source vulnerabilities and emphasized OASIS's role in fostering cooperative security efforts between the AppSec and open source communities.

The timing of OASIS's launch is particularly relevant given the evolving threat landscape. Attackers are increasingly employing AI-assisted techniques, often referred to as "vibe hacking," to discover and exploit vulnerabilities at a pace that outstrips traditional manual defense mechanisms. James Wickett, CEO of DryRun Security, pointed out that the same generative AI technologies accelerating attacks can be harnessed to accelerate defense when combined with expert validation and community collaboration.

OASIS is designed to work in tandem with other significant open source security initiatives, such as OpenAI's Patch the Planet, the Linux Foundation's Akrites, and Anthropic's Project Glasswing. While these efforts often focus on high-priority infrastructure with elite research teams, OASIS aims to scale remediation efforts through a broad base of volunteer AppSec professionals, targeting the vast array of libraries and applications used across the commercial sector. This crowdsourced approach ensures broader coverage and security for the long tail of open source dependencies.

Participation in OASIS is open to a variety of roles, including vulnerability validators, community managers, maintainer liaisons, and automation operators. This vendor-neutral platform provides a low-friction entry point for security practitioners eager to contribute to fixing vulnerabilities, rather than solely focusing on their discovery, thereby strengthening the security posture of the open source software ecosystem.

Synthesized by Vypr AI