Source status: GitHub Security Lab's advisory pages credit either Taskflow Agent or a GHSL-developed AI agent. GitHub's Taskflow campaign articles connect both credit styles to gpt-5.x taskflows followed by manual reproduction, impact assessment, and reporting.
Summary
The CVE-backed subset contains:
- Quarkus CVE-2026-39852;
- Docmost CVE-2026-33193;
- Frappe CVE-2026-39351;
- NocoDB CVE-2026-28397, CVE-2026-28401, CVE-2026-24769, CVE-2026-24768, and CVE-2026-53931;
- Sylius CVE-2026-31820;
- Spree CVE-2026-25757 and CVE-2026-25758;
- Rocket.Chat CVE-2026-28514 and CVE-2026-30833; and
- Wekan CVE-2026-30843 through CVE-2026-30847;
- WooCommerce CVE-2025-15033;
homeassistant-tapo-controlCVE-2025-55192;- Outline CVE-2025-64487 and CVE-2025-68663;
- bit platform CVE-2025-64710; and
- Sentry CVE-2026-26004.
The dominant bug classes are access-control and web-application logic defects, not native-code memory corruption.
Validation boundary
GitHub says Taskflow produced candidate reports, but Security Lab researchers manually reproduced and triaged them before disclosure. The entry counts the 24 public CVEs, not the much larger number of raw model suggestions described in the methodology articles.
References
- GitHub Taskflow audit methodology
- GitHub Taskflow CodeQL-triage methodology
- GitHub Security Lab AI-agent advisory index
- GHSL Quarkus advisory
- GHSL Rocket.Chat advisories
- GHSL NocoDB advisories
- GHSL Outline advisories
- GHSL WooCommerce advisory
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.