{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/oss-crs-aixcc-systems-openssf-2026/",
 "asOf": "2026-09-26",
 "id": "oss-crs-aixcc-systems-openssf-2026",
 "date": "2026-03-09",
 "datePrecision": "day",
 "title": "OSS-CRS makes AIxCC reasoning systems runnable locally; OpenSSF adopts it as a sandbox project",
 "lane": "defense",
 "kind": "tool-release",
 "summary": "Researchers led by Georgia Tech released OSS-CRS, a locally deployable framework for running and combining AIxCC cyber reasoning systems, noting that all seven open-sourced finalist systems depended on competition cloud infrastructure that no longer exists. Porting the winning Atlantis system, they found 10 previously unknown bugs (three high severity) in 8 OSS-Fuzz projects; OpenSSF welcomed OSS-CRS into its AI/ML Security Working Group in April 2026.",
 "whyItMatters": "It addresses the gap between open-sourcing competition systems and making them usable by maintainers.",
 "actors": [
  "georgia-tech",
  "microsoft",
  "team-atlanta",
  "openssf",
  "linux-foundation"
 ],
 "topics": [
  "vulnerability-discovery",
  "vulnerability-repair"
 ],
 "atlas": [
  "tools"
 ],
 "artifacts": [
  "oss-crs",
  "oss-fuzz"
 ],
 "sources": [
  {
   "url": "https://arxiv.org/abs/2603.08566",
   "publisher": "arXiv",
   "title": "OSS-CRS: Liberating AIxCC Cyber Reasoning Systems for Real-World Open-Source Security",
   "date": "2026-03-09",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://openssf.org/blog/2026/04/02/from-aixcc-to-openssf-welcoming-oss-crs-to-advance-ai-driven-open-source-security/",
   "publisher": "OpenSSF",
   "title": "From AIxCC to OpenSSF: Welcoming OSS-CRS to Advance AI Driven Open Source Security",
   "date": "2026-04-02",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "All seven open-sourced AIxCC CRSs remained largely unusable outside their teams because they depended on the retired competition cloud.",
   "locator": "arXiv abstract"
  },
  {
   "fact": "Running ported Atlantis found 10 previously unknown bugs, three high severity, across 8 OSS-Fuzz projects.",
   "locator": "arXiv abstract"
  },
  {
   "fact": "OpenSSF reports Team Atlanta found 25 vulnerabilities across 16 open-source projects, and that manual review of 630 AI-generated patches found 20-40% semantically incorrect despite passing automated validation.",
   "locator": "OpenSSF blog post"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-088"
 ],
 "methods": [
  "ai-vulnerability-discovery",
  "automated-patching",
  "patch-verification"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}