Researchers led by Georgia Tech released OSS-CRS, a locally deployable framework for running and combining AIxCC cyber reasoning systems, noting that all seven open-sourced finalist systems depended on competition cloud infrastructure that no longer exists. Porting the winning Atlantis system, they found 10 previously unknown bugs (three high severity) in 8 OSS-Fuzz projects; OpenSSF welcomed OSS-CRS into its AI/ML Security Working Group in April 2026.
Why it matters
It addresses the gap between open-sourcing competition systems and making them usable by maintainers.
Key facts
As stated in the sources, with where to find them.
- All seven open-sourced AIxCC CRSs remained largely unusable outside their teams because they depended on the retired competition cloud.arXiv abstract
- Running ported Atlantis found 10 previously unknown bugs, three high severity, across 8 OSS-Fuzz projects.arXiv abstract
- OpenSSF reports Team Atlanta found 25 vulnerabilities across 16 open-source projects, and that manual review of 630 AI-generated patches found 20-40% semantically incorrect despite passing automated validation.OpenSSF blog post
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.
Sources
Related records
Feb 7, 2026
Aug 8, 2025
Apr 7, 2026
May 22, 2026
Aug 9, 2023
Mar 6, 2026