Source status: The CNA records and Fluid advisory pages explicitly credit Fluid Attacks' AI SAST Scanner. Human analysts validated the reports before assignment and coordinated disclosure; upstream scores range from medium to high.
Summary
CVE-2026-13229 concerns ticket-article attachment cloning in Zammad. CVE-2026-18403 is an authenticated SQL injection in LimeSurvey’s central participant database, and CVE-2026-63361 is reflected XSS in a LimeSurvey HTML editor popup.
Fluid’s public workflow makes the human role explicit: the scanner generates candidates, while analysts verify reachability, reproduce impact, deduplicate, and coordinate disclosure.
References
- Fluid Attacks: AI SAST CVE workflow
- Fluid Attacks advisories
- CVE record: CVE-2026-13229
- CVE record: CVE-2026-18403
- CVE record: CVE-2026-63361
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.