Skip to content
Menu
Menu

OWASP Launches OASIS To Automate Fixes For Open-Source Software Vulnerabilities

AI-generated fixes will undergo human review before open-source maintainers decide whether to accept, change, or reject them.

 

The Open Worldwide Application Security Project (OWASP) launched a new initiative designed to close the gap between identifying vulnerabilities in open-source software and finding and deploying the fixes. Open-source components are used in a wide range of software, from commercial applications to systems that support critical infrastructure. In its launch announcement, OWASP cited a 2026 Black Duck report finding that open-source code appeared in 98% of the commercial codebases examined.

This means a vulnerability in one widely used component can create risks for many businesses. The problem is growing as automated security tools and AI make it possible to find more flaws, while open-source maintainers must still develop and test the fixes.

The Open Automated Security Initiative for Software, or OASIS, will use AI to generate proposed fixes and application-security professionals to review them. Fixes that pass that review will be submitted to the affected open-source projects, whose maintainers will decide whether to use them.

Rather than creating another tool that identifies problems, OASIS aims to turn vulnerability reports into fixes that open-source maintainers can evaluate and deploy.

AI will generate fixes for human review

OASIS will use automated tools to scan widely used open-source software for vulnerabilities and generate proposed code changes to address them.

Security specialists from companies and other organizations who volunteer through OASIS will review each proposed fix. They will assess whether the reported vulnerability is genuine, whether the change addresses it correctly, and whether the fix could create other security or operational problems.

A fix that clears this review will be considered credible enough for the affected project to evaluate. The project’s maintainers will still test the fix and decide whether to accept, modify, or reject it.

OASIS has not named its first projects

OWASP said hundreds of software-security specialists registered to participate before OASIS formally launched. AppSecAI, Intigriti, and DryRun Security are its founding industry members.

OWASP has not identified the first open-source projects OASIS will examine or said when it expects to submit its first proposed fixes. The initiative plans to track how many fixes open-source maintainers ultimately accept as one measure of whether its approach works.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!