Aisle identified six new security vulnerabilities (CVEs) in curl software days after OpenAI Codex Security and Anthropic Mythos reported zero findings, according to a September 2 blog post on aisle.com. Curl, a widely used data transfer tool, runs on over 20 billion instances globally. This discovery follows curl founder Daniel Stenberg's August 24 update that only three CVEs were pending for the next release.
On August 24, Daniel Stenberg shared on Mastodon that frontier AI cybersecurity systems from Anthropic Mythos and OpenAI Codex Security had not detected any additional vulnerabilities beyond the three pending CVEs. Despite these AI systems showing empty lists for new issues, Aisle's independent analysis uncovered six previously unreported CVEs in curl. This contrast highlights differing detection capabilities among AI security tools, as detailed in the aisle.com blog.
Curl is critical infrastructure software used extensively across the internet for data transfers, making its security paramount. The fact that leading AI security tools from OpenAI and Anthropic found no new vulnerabilities while Aisle discovered six raises questions about the comprehensiveness of current AI-driven cybersecurity scans. This case underscores the challenges in relying solely on AI for vulnerability detection in widely deployed software.
Daniel Stenberg’s public update on August 24 remains the latest official status on curl’s CVEs. The curl project is preparing the next release addressing the known vulnerabilities, while Aisle’s findings add urgency to reassessing AI security tools’ effectiveness in identifying critical software flaws.