Global initiative fights AI with AI and application security community expertise, validating and implementing AI-generated fixes to remediate open source vulnerabilities at scale
SAN FRANCISCO, CA — August 26, 2026
Today, a growing community of application security professionals launched the OWASP Open Automated Security Initiative for Software (OASIS). This global initiative marshals human expertise to deliver crowd-validated vulnerability fixes for the open source software that underlies 98% of commercial codebases (Black Duck 2026 Open Source Security and Risk Analysis Report), including critical infrastructure and commercial software. An OWASP project, OASIS combines donated AI-powered fix automation and validation tooling with human expertise to move open source security from discovery to immediate remediation at scale.
Since opening preliminary sign-ups, OASIS has attracted hundreds of application security professionals from a variety of organizations and industries, alongside founding industry members AppSecAI, Intigriti, and DryRun Security.
“Open source underlies the vast majority of our information economy. Because of the nature of the development process, unremediated vulnerabilities put a huge segment of our critical software infrastructure at risk. OASIS enables the application security and open source communities to cooperatively deliver secure open source software together.” — Chris Holt, Strategic Engagement and Community Architect at Intigriti
Open source underlies nearly every layer of modern digital infrastructure. For decades, the security industry has focused on finding vulnerabilities. While discovery matters, the bottleneck has always been remediation: the cost, process complexity, and specialized expertise required to deliver credible security fixes to application vulnerabilities. These barriers have historically kept many AppSec professionals on the sidelines.
OASIS changes that by leveraging Fix Automation and Validation, an emerging category of AI tools that generate and validate candidate vulnerability fixes as vulnerabilities are found. OASIS establishes a community-driven fix validation layer that makes those fixes trustworthy enough for upstream developer validation and contribution.
With OASIS, fixing vulnerabilities becomes a streamlined, three-part process:
By generating code fixes while actively contributing to the open source ecosystem, OASIS democratizes the vulnerability remediation process. This model shifts the paradigm to a community-driven framework for AI-generated, human-vetted code remediation at scale. It gives application security experts a collaborative platform to augment human capabilities and improve security fixes at open source scale.
"It's always been easier to find than to fix. Even as AI poses an increasing threat, in the right hands, AI-powered tools will shift the balance to the defenders. What OASIS does is finally give those with code security experience the agency to participate. Now, in just a few minutes — you can contribute. We are excited to help the OWASP OASIS community protect the software that quite literally runs the world." — Michael Cartsonis, Co-Founder and VP of Product at AppSecAI
The launch of OASIS comes at a defining moment for software security. "Vibe hacking," the AI-assisted discovery and exploitation of vulnerabilities, is enabling attackers to move faster than any single security team can respond. However, the same generative AI powering these attacks offers a defense: the AppSec community now has the power to find and generate validated fixes at a comparable speed, tipping the balance back toward defenders.
“AI is dramatically increasing the speed at which software is created, and it’s also increasing the speed at which vulnerabilities can be discovered and exploited. OASIS is an important step toward giving defenders the same advantage. By combining AI-powered remediation with independent validation and the expertise of the AppSec community, we can turn vulnerability discovery into credible fixes that maintainers can actually use. We’re proud to support OASIS and help move open source security from finding more problems to fixing them at scale.” — James Wickett, CEO and Co-Founder of DryRun Security
This reality has catalyzed complementary initiatives across the industry. Frontier AI developments like Anthropic's Project Glasswing introduced highly advanced models like Claude Mythos to defenders, while OpenAI’s Patch the Planet and the Linux Foundation's Akrites have mobilized elite research teams and tech coalitions to protect core software infrastructure.
For OASIS, these initiatives are complementary pieces of the same puzzle. While other programs focus on elite, researcher-led intervention for select high-priority infrastructure (like operating systems and browsers), OASIS leverages volunteers from the AppSec community to scale broadly across the open source landscape and address the long tail of software libraries and applications used by enterprises.
To solve a challenge as massive as open source security, the industry requires diverse methodologies. OASIS introduces a distinct and simple approach optimized for broad community scale, contrasting with and complementing private research initiatives.
“The legacy corporate incident response model is fundamentally antiquated in the AI era. It relies on a closed loop of people overseeing every step, which fails the second an attacker leverages automated exploit tools. To survive the threat landscape of 2026 and beyond, our defense has to be entirely community-driven and supercharged with automation. OASIS marshals the wisdom of the application security crowd and the power of open source and multi-vendor AI solutions together to challenge threat velocity at a scale that private, vendor-led initiatives just can't mirror.” — Chris Holt, Intigriti
OASIS operates on a core belief: broad crowd expertise and decentralized participation powered by AI will catch and resolve the vast volume of vulnerabilities hiding in everyday code backlogs. OASIS uses public technologies and open automation pipelines to empower the wider global security workforce.
Open source maintainers face an onslaught of low-fidelity information that overwhelms even large maintenance teams, leaving serious vulnerabilities unresolved.
OASIS acts as a community quality filter. AppSec professionals bring their domain expertise to assess whether a candidate fix is accurate and safe. Human validation is the vital link that converts rapid AI output into a patch a maintainer can trust. It provides a straightforward, vendor-neutral way for AppSec professionals to give back to the open source community while cutting through the noise.
Open source code is present in a vast number of custom enterprise applications. When that code is vulnerable, they are exposed, dependent on maintainers to keep their organizations running.
"I have spent thirty years defending enterprises, and every one of them builds on open source components, which means every one of them inherits any unfixed vulnerabilities in that code. Our industry got very good at finding problems and never solved fixing them at scale. That is what OASIS changes. When the community validates a fix and it lands upstream, thousands of applications get safer at once. That is the highest-leverage work an application security professional can do, and now it is open to all of us." — David Kosorok, Director of Product Security at ACV Auctions
OWASP OASIS is open to security practitioners, developers, researchers, and anyone committed to protecting open source software. Participants can contribute across several key roles:
Learn more and join the initiative at: owasp-oasis.org
The Open Automated Security Initiative for Software (OASIS) is a vendor-neutral, community-driven initiative that mobilizes the Application Security community to deliver validated vulnerability fixes for the open source software that runs the world. By combining AI-powered fix automation with human expert validation, OASIS moves open source security from discovery to remediation at scale. OASIS is an OWASP project.
OWASP does not endorse any product, services, or tools.
The OWASP Foundation is a nonprofit organization that works to improve software security. Through community-led open source software projects, over 260 local chapters worldwide, tens of thousands of members, and leading educational and training conferences, the OWASP Foundation is the source for developers and technologists to secure the web. For nearly two decades, corporations, foundations, developers, and volunteers have supported the OWASP Foundation and its work. To learn more or to become a member, visit owasp.org.
Kira Rose Wojack
Merritt & Rose Communications for OWASP OASIS
+1 415 419-4062
kira@merrittandrose.com