What it is
Atuin is an automated vulnerability discovery engine from Tencent Xuanwu Lab. Tencent’s public write-up describes Atuin as based on large language model technology and says it has found vulnerabilities across important open-source software.
What is verified
The current Bugflation ledger counts the public CVE-backed subset where Atuin is named directly by project or advisory records:
- CVE-2026-23967 in
sm-crypto. - CVE-2026-5807 in HashiCorp Vault.
- CVE-2026-6475 in PostgreSQL.
The Atuin gnark write-up also describes CVE-2025-57801, but that item is not included in the initial Bugflation Atuin count until the final public advisory chain is reviewed in the same pass.
Why it matters
Atuin broadens the ledger beyond US frontier-model labs and security startups. The public evidence shows an LLM-based vulnerability discovery engine earning credits from major infrastructure projects and cryptographic libraries.