All systems

Fluid Attacks Platform

Fluid Attacks AI SAST

A hybrid ML-and-agent SAST workflow whose public advisories retain exact scanner credit after human reachability, exploitability, and disclosure review.

1
Indexed entries
3
CVE IDs tracked
1
Critical/high entries
91%
Evidence index

Fluid Attacks advisories: 33 AI-SAST-attributed CVEs identified in the August audit. Count checked August 19, 2026. Bugflation indexes exact advisories that name the AI SAST Scanner, not the larger candidate-finding funnel. Open tracker.

What it is

Fluid Attacks’ workflow combines a proprietary candidate-ranking model, specialized code-navigation agents, and human security analysts. The analysts validate reachability and exploitability, remove false positives and duplicates, and coordinate public disclosure.

What is verified

Fluid’s affected-project advisories explicitly credit its AI SAST Scanner. This makes the attribution direct under Bugflation’s primary-research-source rule while preserving the material human triage in the workflow.

The first indexed wave contains three August CVEs. Thirty older exact CVEs are documented as a separate reconciliation queue rather than silently absorbed into the headline count.

Sources

Attributed findings

Catalogued entries credited to Fluid Attacks AI SAST.