A recent article by Anil Madhavapeddy argues that AI agents can turn publicly available clues about software vulnerabilities into working exploits, reducing the effectiveness of traditional disclosure embargoes in open source projects. The author highlights the need for faster patching and release processes as the time between vulnerability disclosure and exploitation shrinks.
AI Agents Are Disrupting Open Source Security Disclosure
A recent article by Anil Madhavapeddy argues that AI agents can turn publicly available clues about software vulnerabilities into working exploits, reducing the effectiveness of traditional disclosure embargoes in open source projects.…
infoq.com
Publisher
Oct 3, 2026 at 6:47 AM UTC · Updated vor einem Tag · 2 Min. Lesezeit

Describing his experience fixing a path-traversal vulnerability, Madhavapeddy, professor of computer science at Cambridge and core maintainer of the OCaml compiler, writes:
The patch itself was straightforward and in normal times, the security procedure would have been to fix it privately, inform affected users, and then issue a public advisory. This time around though, I noticed probes in my live webserver logs with the exact bug pattern just minutes after opening the PR to fix the issue.
Traditional security processes rely on embargoing vulnerabilities, assuming that keeping technical details secret protects users. However, AI agents can independently research vulnerabilities from limited clues: in a recent study, a GPT-4 agent exploited 87% of vulnerabilities in a 15-vulnerability benchmark when given CVE descriptions, compared with 7% without them. Arguing that"bugonomics" are now against OSS maintainers, Madhavapeddy adds:
Article Intelligence
Topics
Regulation Signal
in progressUpdated vor 2 Monaten
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
