Introducing OWASP OASIS, a New Initiative to Fight Back Against AI and Human Exploits of Open Source Software Vulnerabilities

Aug 26, 2026, 5:00:00 AM | News Introducing OWASP OASIS, a New Initiative to Fight Back Against AI and Human Exploits of Open Source Software Vulnerabilities

OWASP OASIS launches: AI-powered fix automation plus AppSec community validation, delivering credible security patches for open source at scale.

Global initiative fights AI with AI and application security community expertise, validating and implementing AI-generated fixes to remediate open source vulnerabilities at scale

SAN FRANCISCO, CA — August 26, 2026

  • An Effective Model for Open Source Security: The Open Automated Security Initiative for Software (OASIS) provides human validation that turns AI-generated fix candidates into vetted patches, offering credible, clear fixes for open source maintainers and cutting complexity and noise.
  • Complementing Ecosystem Milestones: Designed to work alongside recent enterprise-led infrastructure initiatives like OpenAI’s Patch the Planet, the Linux Foundation’s Akrites, and Anthropic’s Project Glasswing, OASIS brings a broad, community-scale approach to securing open source code.
  • Community Momentum and Scale: Since opening to sign-ups, OASIS has attracted hundreds of application security champions across industries around the world, alongside founding sponsors AppSecAI, Intigriti, and DryRun Security.
  • Built for the AI Threat Era: As "vibe hacking" and AI-driven exploits surge and Mythos dominates the headlines, OASIS offers a vendor-neutral, community-led way for AppSec professionals to collectively tip the balance back toward defenders.
  • Fixes are atomic and open-source: Creating opportunities for organizations and teams to secure their applications at higher speed.

Today, a growing community of application security professionals launched the OWASP Open Automated Security Initiative for Software (OASIS). This global initiative marshals human expertise to deliver crowd-validated vulnerability fixes for the open source software that underlies 98% of commercial codebases (Black Duck 2026 Open Source Security and Risk Analysis Report), including critical infrastructure and commercial software. An OWASP project, OASIS combines donated AI-powered fix automation and validation tooling with human expertise to move open source security from discovery to immediate remediation at scale.

Since opening preliminary sign-ups, OASIS has attracted hundreds of application security professionals from a variety of organizations and industries, alongside founding industry members AppSecAI, Intigriti, and DryRun Security.

“Open source underlies the vast majority of our information economy. Because of the nature of the development process, unremediated vulnerabilities put a huge segment of our critical software infrastructure at risk. OASIS enables the application security and open source communities to cooperatively deliver secure open source software together.” — Chris Holt, Strategic Engagement and Community Architect at Intigriti

What OWASP OASIS Is

Open source underlies nearly every layer of modern digital infrastructure. For decades, the security industry has focused on finding vulnerabilities. While discovery matters, the bottleneck has always been remediation: the cost, process complexity, and specialized expertise required to deliver credible security fixes to application vulnerabilities. These barriers have historically kept many AppSec professionals on the sidelines.

OASIS changes that by leveraging Fix Automation and Validation, an emerging category of AI tools that generate and validate candidate vulnerability fixes as vulnerabilities are found. OASIS establishes a community-driven fix validation layer that makes those fixes trustworthy enough for upstream developer validation and contribution.

With OASIS, fixing vulnerabilities becomes a streamlined, three-part process:

  1. AI Pipeline: Automated tools scan widely used open source repositories and generate candidate security fixes at scale. Found vulnerabilities always come with a candidate fix
  2. Expert Community Validation: A community of AppSec professionals and agents reviews the candidate fixes, assesses correctness and safety, and determines which ones are credible, reducing complexity – and thus validation – time to minutes
  3. Upstream Contribution: Validated fixes are provided to open source teams as credible, community-validated security patches for consideration, allowing maintainers to quickly validate them for functionality and performance and integrate them at their discretion

By generating code fixes while actively contributing to the open source ecosystem, OASIS democratizes the vulnerability remediation process. This model shifts the paradigm to a community-driven framework for AI-generated, human-vetted code remediation at scale. It gives application security experts a collaborative platform to augment human capabilities and improve security fixes at open source scale.

"It's always been easier to find than to fix. Even as AI poses an increasing threat, in the right hands, AI-powered tools will shift the balance to the defenders. What OASIS does is finally give those with code security experience the agency to participate. Now, in just a few minutes — you can contribute. We are excited to help the OWASP OASIS community protect the software that quite literally runs the world." — Michael Cartsonis, Co-Founder and VP of Product at AppSecAI

Why Now? Ecosystem Synergy in the AI Era

The launch of OASIS comes at a defining moment for software security. "Vibe hacking," the AI-assisted discovery and exploitation of vulnerabilities, is enabling attackers to move faster than any single security team can respond. However, the same generative AI powering these attacks offers a defense: the AppSec community now has the power to find and generate validated fixes at a comparable speed, tipping the balance back toward defenders.

“AI is dramatically increasing the speed at which software is created, and it’s also increasing the speed at which vulnerabilities can be discovered and exploited. OASIS is an important step toward giving defenders the same advantage. By combining AI-powered remediation with independent validation and the expertise of the AppSec community, we can turn vulnerability discovery into credible fixes that maintainers can actually use. We’re proud to support OASIS and help move open source security from finding more problems to fixing them at scale.” — James Wickett, CEO and Co-Founder of DryRun Security

This reality has catalyzed complementary initiatives across the industry. Frontier AI developments like Anthropic's Project Glasswing introduced highly advanced models like Claude Mythos to defenders, while OpenAI’s Patch the Planet and the Linux Foundation's Akrites have mobilized elite research teams and tech coalitions to protect core software infrastructure.

For OASIS, these initiatives are complementary pieces of the same puzzle. While other programs focus on elite, researcher-led intervention for select high-priority infrastructure (like operating systems and browsers), OASIS leverages volunteers from the AppSec community to scale broadly across the open source landscape and address the long tail of software libraries and applications used by enterprises.

The OWASP OASIS Approach: Open, Democratic, and Vendor-Agnostic

To solve a challenge as massive as open source security, the industry requires diverse methodologies. OASIS introduces a distinct and simple approach optimized for broad community scale, contrasting with and complementing private research initiatives.

“The legacy corporate incident response model is fundamentally antiquated in the AI era. It relies on a closed loop of people overseeing every step, which fails the second an attacker leverages automated exploit tools. To survive the threat landscape of 2026 and beyond, our defense has to be entirely community-driven and supercharged with automation. OASIS marshals the wisdom of the application security crowd and the power of open source and multi-vendor AI solutions together to challenge threat velocity at a scale that private, vendor-led initiatives just can't mirror.” — Chris Holt, Intigriti

OASIS operates on a core belief: broad crowd expertise and decentralized participation powered by AI will catch and resolve the vast volume of vulnerabilities hiding in everyday code backlogs. OASIS uses public technologies and open automation pipelines to empower the wider global security workforce.

Why Open Source Needs OWASP OASIS

Open source maintainers face an onslaught of low-fidelity information that overwhelms even large maintenance teams, leaving serious vulnerabilities unresolved.

OASIS acts as a community quality filter. AppSec professionals bring their domain expertise to assess whether a candidate fix is accurate and safe. Human validation is the vital link that converts rapid AI output into a patch a maintainer can trust. It provides a straightforward, vendor-neutral way for AppSec professionals to give back to the open source community while cutting through the noise.

Why Enterprise Users need OWASP OASIS

Open source code is present in a vast number of custom enterprise applications. When that code is vulnerable, they are exposed, dependent on maintainers to keep their organizations running.

"I have spent thirty years defending enterprises, and every one of them builds on open source components, which means every one of them inherits any unfixed vulnerabilities in that code. Our industry got very good at finding problems and never solved fixing them at scale. That is what OASIS changes. When the community validates a fix and it lands upstream, thousands of applications get safer at once. That is the highest-leverage work an application security professional can do, and now it is open to all of us." — David Kosorok, Director of Product Security at ACV Auctions

How to Get Involved

OWASP OASIS is open to security practitioners, developers, researchers, and anyone committed to protecting open source software. Participants can contribute across several key roles:

  • Vulnerability Validators: Reviewing and approving candidate AI-generated fixes.
  • Repo Community Managers: Moderating and managing contributors and maintainer activities.
  • Maintainer Liaisons: Managing upstream submissions and maintainer communication.
  • Automation Operators: Running scanning and fix-generation pipelines.

Learn more and join the initiative at: owasp-oasis.org


About OWASP OASIS

The Open Automated Security Initiative for Software (OASIS) is a vendor-neutral, community-driven initiative that mobilizes the Application Security community to deliver validated vulnerability fixes for the open source software that runs the world. By combining AI-powered fix automation with human expert validation, OASIS moves open source security from discovery to remediation at scale. OASIS is an OWASP project.

OWASP does not endorse any product, services, or tools.

About OWASP

The OWASP Foundation is a nonprofit organization that works to improve software security. Through community-led open source software projects, over 260 local chapters worldwide, tens of thousands of members, and leading educational and training conferences, the OWASP Foundation is the source for developers and technologists to secure the web. For nearly two decades, corporations, foundations, developers, and volunteers have supported the OWASP Foundation and its work. To learn more or to become a member, visit owasp.org.

Media Contact

Kira Rose Wojack
Merritt & Rose Communications for OWASP OASIS
+1 415 419-4062
kira@merrittandrose.com

Written By: Bruce Fram

Bruce Fram brings a rare combination of serial entrepreneurship and deep application security expertise to automated code remediation. As founder and CEO of AppSecAI and CEO of six enterprise software companies—including his role as founding CEO of Contrast Security—Bruce has spent decades at the intersection of developer productivity and security eff ectiveness. At Contrast, he helped bring Contrast’s IAST technology to Fortune 500 companies and transform their approach to application security. His experience scaling engineering and security programs across organizations gives him unique insight into what delivers ROI—and what doesn’t.