OWASP launches OASIS to speed AI-assisted open source vulnerability fixes
A new OWASP project called OASIS launched Aug. 26 to help application security professionals generate, validate and upstream open source security fixes faster. The initiative aims to counter AI-assisted attacks by pairing donated automation with human review across widely used software.
Why it matters: - Open source software underlies 98% of commercial codebases, including critical infrastructure and enterprise applications. - OASIS is designed to move security work from vulnerability discovery to remediation at scale. - The initiative could help close a long-standing gap in application security: finding issues faster than teams can fix them.
What happened: - A community of application security professionals launched OWASP Open Automated Security Initiative for Software, or OASIS, on Aug. 26, 2026. - The project is an OWASP initiative and is vendor-neutral, community-driven and open to the AppSec community. - Hundreds of AppSec professionals from multiple industries have joined, alongside founding industry members AppSecAI, Intigriti and DryRun Security. - The initiative is available at owasp-oasis.org.
The details: - OASIS combines donated AI-powered fix automation and validation tooling with human expertise. - The project uses a three-part workflow: AI tools scan open source repositories and generate candidate fixes, experts validate those fixes, and approved fixes are passed to open source maintainers for review and possible upstream contribution. - OASIS says its validation layer can reduce review time to minutes. - Human review is intended to turn rapid AI output into patches maintainers can trust. - The model is meant to help maintainers quickly assess functionality and performance before integrating fixes at their discretion. - OWASP said the project is meant to democratize vulnerability remediation with a collaborative platform that augments human capability.
Between the lines: - The launch reflects a shift in AppSec from detection-first workflows to repair-first workflows. - The initiative is timed to counter “vibe hacking,” the AI-assisted discovery and exploitation of vulnerabilities, which can outpace manual response. - OASIS positions itself as broader than other industry efforts by relying on volunteers and open participation rather than a researcher-led model focused on a smaller set of critical systems. - That approach could matter most for the long tail of open source libraries and applications used across enterprises. - Open source maintainers face a high volume of low-fidelity vulnerability information, and OASIS is meant to act as a community quality filter.
What's next: - OASIS will recruit more application security professionals to review candidate fixes and contribute validated patches upstream. - The project aims to scale across the open source ecosystem and help maintainers ship credible fixes faster. - OWASP and OASIS supporters are framing the effort as a way to make remediation more accessible to more security practitioners.
The bottom line: - OASIS tries to turn AI from an attack accelerant into a defense tool by combining automated fix generation with human validation for open source security.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Business Herald Online
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.