OWASP has launched the Open Automated Security Initiative for Software (OASIS), a global community effort designed to close the gap between finding vulnerabilities in open source code and actually fixing them.
Announced on August 26, 2026, in San Francisco, the initiative pairs AI-generated fix candidates with human validation from application security professionals, aiming to deliver credible, ready-to-use patches to open source maintainers instead of just longer vulnerability lists.
Open source software underlies roughly 98% of commercial codebases, according to the Black Duck 2026 Open Source Security and Risk Analysis Report, yet maintainers are routinely overwhelmed by scanning tools that flag issues without offering usable remediation paths. OASIS addresses that bottleneck through a three-stage process.
Automated tooling first scans widely used repositories and generates candidate fixes as vulnerabilities surface. A community of AppSec practitioners and agents then reviews each candidate for correctness and safety, cutting validation time down to minutes.
Finally, vetted patches are submitted upstream, giving maintainers a trustworthy starting point they can adapt to their own codebase rather than a raw AI suggestion, complementing modern open-source vulnerability scanner workflows.
Since opening early sign-ups, OASIS has drawn hundreds of application security professionals across industries, backed by founding sponsors AppSecAI, Intigriti, and DryRun Security.
As detailed in the OWASP OASIS announcement, Chris Holt, Strategic Engagement and Community Architect at Intigriti, said open source underpins the majority of the information economy, making unremediated vulnerabilities a systemic risk, and that OASIS lets the AppSec and open source communities cooperatively deliver secure software together.
The timing reflects a shifting threat landscape. Attackers are increasingly using “vibe hacking,” AI-assisted vulnerability discovery and exploitation that outpaces manual defense.
James Wickett, CEO of DryRun Security, noted that the same generative AI accelerating attacks can accelerate defense when paired with independent validation and community expertise.
Michael Cartsonis of AppSecAI added that OASIS finally gives security professionals with code-review experience a fast, low-friction way to contribute.
| Stage / Component | Process & Operational Model | Strategic Impact |
| Automated Scanning & Generation | AI-driven tooling scans repos and crafts patch candidates | Accelerates initial remediation proposals for newly found CVEs |
| AppSec Community Validation | Human-in-the-loop expert review and agent validation | Cuts review cycles to minutes and eliminates false-positive fixes |
| Upstream Submission | Delivery of vetted, ready-to-merge patches to maintainers | Reduces maintainer burden with production-grade remediation |
| Ecosystem Collaboration | Vendor-neutral backing (OWASP, Intigriti, DryRun Security) | Secures long-tail open source dependencies across commercial stacks |
OASIS is positioned as a complement to enterprise-led efforts such as OpenAI’s Patch the Planet, the Linux Foundation’s Akrites, and Anthropic’s Project Glasswing, which focus elite research teams on high-priority infrastructure like operating systems and browsers.
OASIS instead scales through volunteer AppSec crowds to cover the long tail of libraries and applications enterprises actually run, an approach David Kosorok, Director of Product Security at ACV Auctions, called the highest-leverage work in application security, since one validated upstream fix can secure thousands of downstream applications simultaneously, bolstering defense against offensive vulnerability discovery tool automation.
Participation is open through several roles, including vulnerability validators, repo community managers, maintainer liaisons, and automation operators, making OASIS a vendor-neutral entry point for security practitioners wanting to help fix, not just find, the vulnerabilities threatening the open source software that powers modern infrastructure.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post OWASP Launches OASIS AI Initiative to Fix Open Source Vulnerabilities at Scale appeared first on Cyber Security News.
