Archive for OWASP OASIS

Introducing OWASP OASIS

Posted in Commentary with tags on September 1, 2026 by itnerd

Today, a community of application security professionals launched OWASP Open Automated Security Initiative for Software (OASIS). This global initiative marshals human expertise to deliver crowd-validated vulnerability fixes for the open source software that underlies 98% of commercial codebases, including critical infrastructure and commercial software. OWASP OASIS combines donated AI-powered fix automation and validation tooling with human expertise to move open source security from discovery to immediate remediation at scale.

OASIS has attracted hundreds of AppSec professionals from a variety of industries, alongside founding industry members AppSecAI, Intigriti, and DryRun Security.

What OWASP OASIS Is

For decades, the security industry has focused on finding vulnerabilities. The bottleneck has always been remediation: the cost, process complexity, and specialized expertise required to deliver credible security fixes for vulnerabilities.

OASIS changes that by leveraging Fix Automation and Validation, an emerging category of AI tools that generate and validate candidate fixes as vulnerabilities are found. OASIS’s community-driven validation layer makes those fixes trustworthy for upstream developer validation and contribution.

The three-part process:

  1. AI Pipeline: Automated tools scan open source repositories and generate candidate security fixes at scale. Found vulnerabilities always come with a candidate fix
  1. Expert Community Validation: The community reviews fixes, assesses correctness and safety, and determines which ones are credible, reducing validation time to minutes
  1. Upstream Contribution: Validated fixes are provided to open source teams as credible, community-validated security patches for consideration, allowing maintainers to quickly validate them for functionality and performance and integrate them at their discretion

By generating code fixes while contributing to the open source ecosystem, OASIS democratizes the vulnerability remediation process with a collaborative platform to augment human capabilities and improve security fixes at scale.

Why Now?

The launch of OASIS comes at a defining moment. “Vibe hacking,” the AI-assisted discovery and exploitation of vulnerabilities, enables attackers to move faster than security teams can respond. However, the same generative AI powering attacks offers a defense: the AppSec community now has the power to find and generate validated fixes at comparable speed.

This reality has catalyzed complementary initiatives across the industry. Frontier AI developments like Anthropic’s Project Glasswing introduced highly advanced models like Claude Mythos to defenders, while OpenAI’s Patch the Planet and the Linux Foundation’s Akrites have mobilized elite research teams and tech coalitions to protect core software infrastructure.

While these programs focus on researcher-led intervention for select high-priority infrastructure, OASIS is open, democratic, and vendor-agnostic. It leverages volunteers from the AppSec community to scale broadly across the open source landscape and address the long tail of software libraries and applications used by enterprises.

Why Open Source Needs OWASP OASIS

Open source maintainers face an onslaught of low-fidelity information.

OASIS acts as a community quality filter. AppSec experts assess whether a candidate fix is accurate and safe. Human validation converts rapid AI output into a patch a maintainer can trust. It provides a straightforward, vendor-neutral way for AppSec professionals to give back to the open source community.

Why Enterprise Users need OWASP OASIS

Open source code underlies countless custom enterprise applications.  When that code is vulnerable, they are exposed, dependent on maintainers to keep organizations running. 

How to Get Involved

Join the initiative at owasp-oasis.org