Skip to content

[CVE and AI virtual conference] AI-enabled vulnerability assessment in open source software #55

Description

@JKC-ENISA

Dear CVE secretariat,

we are submitting the following session proposal:

Format: Moderated Discussion
Theme Alignment: AI-enabled vulnerability assessment in open source software, developing and facilitating open source resilience from scanning and validation to CVE assignment and coordinated disclosure
Contributors: Francesca Spidalieri, Johannes Clos


Abstract:

As AI-enabled tools make it increasingly possible to scan open-source libraries, components, and repositories at much greater speed and scale, the vulnerability management community will need to address not only how vulnerabilities are discovered, but also how they are validated, coordinated, assigned CVEs, responsibly disclosed, and remediated in ways that do not overburden FOSS maintainers or create additional risk for downstream users.

Possible discussion questions could include:

  • How should the CVE community prepare for the increased speed, scale, and volume of vulnerabilities discovered in open-source libraries, components, and repositories through AI-enabled scanning?
  • What validation, triage, and quality-control mechanisms are needed to distinguish actionable vulnerabilities from low-quality, duplicative, or non-exploitable findings?
  • Who should assign CVEs for vulnerabilities discovered through AI-enabled open-source scanning, particularly when the affected project has no CNA, limited maintainer capacity, or unclear ownership?
  • Which organizations or initiatives are already scanning open-source libraries, components, and repositories for vulnerabilities, and what operational lessons can be shared with the CVE community?
  • How can initiatives such as Akrites, OpenSSF/Alpha-Omega, and similar efforts help avoid duplication, fragmentation, or overwhelming open-source maintainers?

Motivation:

ENISA would be very interested in contributing to and potentially helping to lead such a session, given our role as both a CNA and CVE Root for European entities, our work on EU Vulnerability Services, our support for EU Member States / national CSIRTs with CVD processes, and our multiple ongoing activities under the recently released EU Action Plan on Cybersecurity and AI.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    AI ForumSuggested issues/topics for the CVE Program virtual AI Forum on July 30, 2026

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions