fix: resolve the 10 records flagged by the researcher/disclosure check - #158
Merged
Merged
Conversation
Catches the pattern behind the AVE-2026-00060 and repo-forensics attribution mistakes: researcher field names an AVE maintainer while references contains what reads as the actual external disclosure. Warning only, not a hard failure, some records are genuinely original cataloguing with no external discloser. Tested against four cases before integration: the real mistake, its corrected form, a genuine original record, and an implementation-only reference, all four behave correctly.
Follow-up to #157 (feat: soft researcher/disclosure misattribution check). Went through each of the 10 warnings individually rather than batch-applying one rule: Four were real misattributions, a real, specific, named external discloser exists and wasn't reflected in researcher: - AVE-2026-00029: Nicholas Boucher & Ross Anderson (Trojan Source, arXiv 2111.00169 / CVE-2021-42574) -- the paper the record's own references already cited. - AVE-2026-00052: Peter Girnus (@gothburz), Trend Research / Zero Day Initiative -- confirmed via ZDI-26-021, added as an explicit reference entry alongside the existing CVE/Snyk/GitLab citations. - AVE-2026-00054: Jeremy Brown, coordinated through CERT/CC (VU#414811) -- added as an explicit reference entry; the existing CVE reference only said "CERT/CC-reported" without a URL. - AVE-2026-00056: Aim Labs (EchoLeak, CVE-2025-32711) -- credited via their own arXiv paper (2509.10540), not their company domain, which now redirects entirely to an unrelated acquirer's site and would have pointed at the wrong thing. Six were false positives on the check's own keyword match (matched on "Disclosure" inside OWASP's own category title, or on a bare "CVE" tag used to bundle multiple independent incidents), confirmed genuinely original AVE cataloguing after reading each record's actual references: AVE-2026-00003, 00013, 00026, 00039, 00047 cite only generic frameworks (CWE/ATT&CK/OWASP) or general background academic literature, not a specific discloser of this exact mechanism. AVE-2026-00053 synthesizes three independently-disclosed CVEs across three unrelated MCP implementations into one behavioral class -- the pattern recognition is AVE's own contribution, crediting any single one of the three would misattribute the actual synthesis work. All six got the pre-existing team-name-to-individual-name fix only (Bawbel Security Research Team -> Saray Chak), no re-attribution. The check still flags these six going forward, correctly -- it has no way to know a human already reviewed them, and it shouldn't be silenced by one reviewer's private judgment call.
Merged
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #157. Went through each of the 10 warnings that check surfaced against the live corpus, individually -- not batch-applying one rule to all ten.
Real misattributions (4) -- re-attributed with verified sources
False positives (6) -- confirmed genuinely original AVE cataloguing
AVE-2026-00003,00013,00026,00039,00047cite only generic frameworks (CWE/ATT&CK/OWASP) or general background academic literature (e.g. a 2019 paper on secret leakage in public GitHub repos generally, not this specific mechanism), not a named discloser of this exact behavioral class -- the check matched on the word "Disclosure" inside OWASP's own category title.AVE-2026-00053synthesizes three independently-disclosed CVEs across three unrelated MCP implementations into one behavioral class; the pattern recognition connecting them is AVE's own contribution, so crediting any single one of the three would misattribute the actual synthesis work. All six got the pre-existing team-name-to-individual-name fix only (Bawbel Security Research Team -> Saray Chak), no re-attribution.The check (#157) still flags these six going forward, correctly -- it can't know a human already reviewed them, and it shouldn't be silenced by one reviewer's private judgment call.
Test plan
python3 scripts/validate_records.py-- 76/76 valid, exits 0, warnings now show only the 6 confirmed-original recordspython3 scripts/validate_crosswalks.py-- 6/6 validpytest tests/ -x -q-- 305 passed