New AI tools target key vulnerabilities in thousands of open source applications

Dutch and Iranian security researchers have created an automated Genai tool that can scan massive open source repositories and patched fragile code that can hurt applications.
The tool tested by scanning GitHub for specific path traversal vulnerabilities in the Node.js project, which identified 1,756 vulnerable projects, some of which were described as “very impactful” and resulted in 63 projects being patched so far.
This tool opens up the possibility that Genai platforms, such as the Genai platform, will automatically create and distribute patches in the code repository, greatly improving the security of open source applications.
However, this study, described in a recently published paper, also points to serious limitations in the use of AI, which will require repairs to make the solution effective. Automatic patching with large language models (LLM) can significantly improve scalability, but this patch may introduce other bugs.