Source status: GitHub, HashiCorp, and PostgreSQL public records credit Atuin Automated Vulnerability Discovery Engine. Tencent Xuanwu Lab's Atuin write-up describes the system as based on large language model technology.
Summary
Atuin now has multiple public CVE-backed credits:
- CVE-2026-23967, an SM2-DSA signature malleability issue in
sm-crypto. - CVE-2026-5807, a HashiCorp Vault denial of service involving root-token generation and rekey operations.
- CVE-2026-6475, a PostgreSQL
pg_basebackupandpg_rewindsymlink-following issue that can overwrite unrelated files.
Attribution
The public project advisories name Atuin Automated Vulnerability Discovery Engine. The separate Tencent Xuanwu Lab write-up establishes that Atuin is an automated vulnerability discovery system based on large language model technology, satisfying the AI-system requirement without relying on inference from the advisory names alone.
References
- Tencent Xuanwu Lab: Atuin gnark write-up
- GitHub Advisory: sm-crypto CVE-2026-23967
- HashiCorp: CVE-2026-5807
- PostgreSQL: CVE-2026-6475
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.