Dear CVE secretariat,
we are submitting the following session proposal:
Format: Moderated Discussion
Theme Alignment: AI-enabled vulnerability assessment in open source software, developing and facilitating open source resilience from scanning and validation to CVE assignment and coordinated disclosure
Contributors: Francesca Spidalieri, Johannes Clos
Abstract:
As AI-enabled tools make it increasingly possible to scan open-source libraries, components, and repositories at much greater speed and scale, the vulnerability management community will need to address not only how vulnerabilities are discovered, but also how they are validated, coordinated, assigned CVEs, responsibly disclosed, and remediated in ways that do not overburden FOSS maintainers or create additional risk for downstream users.
Possible discussion questions could include:
- How should the CVE community prepare for the increased speed, scale, and volume of vulnerabilities discovered in open-source libraries, components, and repositories through AI-enabled scanning?
- What validation, triage, and quality-control mechanisms are needed to distinguish actionable vulnerabilities from low-quality, duplicative, or non-exploitable findings?
- Who should assign CVEs for vulnerabilities discovered through AI-enabled open-source scanning, particularly when the affected project has no CNA, limited maintainer capacity, or unclear ownership?
- Which organizations or initiatives are already scanning open-source libraries, components, and repositories for vulnerabilities, and what operational lessons can be shared with the CVE community?
- How can initiatives such as Akrites, OpenSSF/Alpha-Omega, and similar efforts help avoid duplication, fragmentation, or overwhelming open-source maintainers?
Motivation:
ENISA would be very interested in contributing to and potentially helping to lead such a session, given our role as both a CNA and CVE Root for European entities, our work on EU Vulnerability Services, our support for EU Member States / national CSIRTs with CVD processes, and our multiple ongoing activities under the recently released EU Action Plan on Cybersecurity and AI.
Dear CVE secretariat,
we are submitting the following session proposal:
Format: Moderated Discussion
Theme Alignment: AI-enabled vulnerability assessment in open source software, developing and facilitating open source resilience from scanning and validation to CVE assignment and coordinated disclosure
Contributors: Francesca Spidalieri, Johannes Clos
Abstract:
As AI-enabled tools make it increasingly possible to scan open-source libraries, components, and repositories at much greater speed and scale, the vulnerability management community will need to address not only how vulnerabilities are discovered, but also how they are validated, coordinated, assigned CVEs, responsibly disclosed, and remediated in ways that do not overburden FOSS maintainers or create additional risk for downstream users.
Possible discussion questions could include:
Motivation:
ENISA would be very interested in contributing to and potentially helping to lead such a session, given our role as both a CNA and CVE Root for European entities, our work on EU Vulnerability Services, our support for EU Member States / national CSIRTs with CVD processes, and our multiple ongoing activities under the recently released EU Action Plan on Cybersecurity and AI.