All findings

CVE-2026-39852 + 23 more high

GitHub Taskflow Agent produces 24 public CVEs across thirteen projects

GitHub Security Lab's AI-powered Taskflow campaigns yielded 24 unique CVEs after human reproduction and triage across thirteen web applications and frameworks.

Bug class
Authorization bypass, data exposure, XSS, CSRF, and business-logic vulnerabilities
Affected codebase
Quarkus, Docmost, Frappe, NocoDB, Sylius, Spree, Rocket.Chat, Wekan, WooCommerce, homeassistant-tapo-control, Outline, bit platform, and Sentry
Credited system
GitHub Security Lab Taskflow Agent
Disclosed
May 6, 2026
Attribution
Direct source attribution
Severity
high
Source status: GitHub Security Lab's advisory pages credit either Taskflow Agent or a GHSL-developed AI agent. GitHub's Taskflow campaign articles connect both credit styles to gpt-5.x taskflows followed by manual reproduction, impact assessment, and reporting.

Summary

The CVE-backed subset contains:

The dominant bug classes are access-control and web-application logic defects, not native-code memory corruption.

Validation boundary

GitHub says Taskflow produced candidate reports, but Security Lab researchers manually reproduced and triaged them before disclosure. The entry counts the 24 public CVEs, not the much larger number of raw model suggestions described in the methodology articles.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.