Aisle finds 6 curl vulnerabilities with CVEs missed by AI
Technology
Aisle, an AI-native vulnerability-management startup, just spotted six new vulnerabilities in the popular open-source tool curl: ones that even top AI systems like Anthropic's Mythos and OpenAI Codex Security missed.
All six issues got official CVE numbers and were patched up in curl's latest update on September 2, 2026.
Aisle used smaller, focused AI models
What's cool is how Aisle used smaller, focused AI models (instead of just throwing huge ones at the problem) to catch these bugs.
curl's founder Daniel Stenberg praised their collaboration and the quality of the reports.
Their careful process led to six out of 29 reported issues being confirmed as real threats, a win that's earned them praise from big names across tech, including folks at Linux and Red Hat.