GHSA-5XXX-QHH7-9287
2026-08-10
gitpython-developers/gitpython
Repo.blame contents reads arbitrary file
AI root cause · Injection & unsafe execution · Incomplete remediation
See root cause and fix →Loading…
Georgia Tech SSLab · security research
195 confirmed vulnerabilities where AI-written code introduced, enabled, or failed to close the flaw.
Disclosure trend
When these cases were publicly disclosed.
| Month | Findings |
|---|---|
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 2 |
| Dec 2025 | 1 |
| Jan 2026 | 0 |
| Feb 2026 | 18 |
| Mar 2026 | 30 |
| Apr 2026 | 30 |
| May 2026 | 31 |
| Jun 2026 | 28 |
| Jul 2026 | 43 |
| Aug 2026 | 9 |
* Aug 2026 is partial.
Patterns
AI tooling
184 of 195 findings name a tool on every candidate commit.
Base rate sibling
23,977 AI-marked of 160,719 commits, same repos and window. Absolute case counts mean nothing without this denominator.
cases 81.5% (150) · 1.07× cases vs commits
cases 7.6% (14) · 0.40× cases vs commits
cases 4.3% (8) · 1.40× cases vs commits
cases 0.5% (1) · 0.53× cases vs commits
cases 6.0% (11) · 5.87× cases vs commits
Claude self-marks nearly every commit; GPT/Codex and Cursor usually leave no marker, so their shares are floors and ratios above 1× are upper bounds, not proof a tool writes worse code. A ratio near 1× means cases track usage.
Root causes
One root-cause category per finding.
Languages
Top languages; all remain available in Findings.
Projects
Top repositories; filter the full index in Findings.
Featured findings
GHSA-5XXX-QHH7-9287
2026-08-10
gitpython-developers/gitpython
AI root cause · Injection & unsafe execution · Incomplete remediation
See root cause and fix →GHSA-WVPP-8HX9-P66J
2026-08-07
gitpython-developers/gitpython
AI root cause · Injection & unsafe execution · Direct introduction
See root cause and fix →CVE-2026-18980 (GHSA-CW23-QWR7-C655)
2026-08-06
nearai/ironclaw
AI root cause · Injection & unsafe execution · Causal contribution
See root cause and fix →CVE-2026-50568 (GHSA-R5JH-Q2MW-GCX4)
2026-07-28
fission/fission
AI-written code was flawed · Validation & fail-open logic · New attack surface
See root cause and fix →CVE-2026-59233 (GHSA-4FXP-2M36-QV64)
2026-08-10
roskus/prospero-flow-crm
AI root cause · Authentication & access control · Incomplete remediation
See root cause and fix →GHSA-3WXW-XV34-2FRG
2026-08-10
gitpython-developers/gitpython
AI root cause · Path & link handling · Incomplete remediation
See root cause and fix →Media coverage
Q&A