Skip to content

fix: AVE-2026-00048 attribution and remediation branding - #202

Merged
chaksaray merged 1 commit into
developfrom
fix/ave-00048-attribution-and-branding
Aug 25, 2026
Merged

chaksaray merged 1 commit into
developfrom
fix/ave-00048-attribution-and-branding

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Two issues found on a record currently being read by an external OpenCRE contributor.

Researcher attribution: still had the deprecated Bawbel Security Research Team team-name convention. Before fixing, read the full Cohen et al. paper (arXiv:2403.02817) cited in this record's own references, to check whether it's actually the source of the delegation-inheritance mechanism rather than defaulting either way. It isn't — the paper describes a self-replicating worm (Morris-II) propagating via RAG-based indirect prompt injection across GenAI applications, a related but structurally different problem. A full-text search for delegation/sub-agent/permission-inheritance/trust-boundary language returns zero substantive matches. This is AVE's own synthesis of CWE-269/284 into the agentic delegation context, so researcher is corrected to Saray Chak; Cohen et al. stays cited in references as related context, unchanged.

Remediation branding: point 5 named a specific Bawbel product feature (bawbel-accept). Replaced with a generic, vendor-neutral time-bounded-grant control description.

Corpus-wide check (both patterns, not assumed isolated): branded remediation text was isolated to this one record. Stale researcher attribution was not — 50 of 80 records still carry Bawbel Security Research Team, far more than this task's premise of a single record missed by an already-complete pass. Not fixed here, per this task's own scope instruction — flagging as a separate, deliberate follow-up audit rather than silently expanding this PR.

…026-00048

researcher field still carried the deprecated team-name convention.
Researched whether Cohen et al. (arXiv:2403.02817, cited in this
record's own references) is the actual source of the delegation-
inheritance mechanism before deciding attribution: read the full
paper, it describes a self-replicating worm (Morris-II) propagating
via RAG-based indirect prompt injection across GenAI applications, a
related but structurally different problem, not sub-agent permission
inheritance. A full-text search for delegation/sub-agent/inheritance/
trust-boundary language returns zero substantive matches. This is
AVE's own synthesis of CWE-269/284 into the agentic delegation
context; researcher corrected to Saray Chak, Cohen et al. stays cited
as related context in references, unchanged.

Also removes a Bawbel-branded product reference (bawbel-accept) from
the remediation text, replaced with a generic, vendor-neutral
time-bounded-grant control description.

Checked the rest of the corpus for both patterns rather than assume
this record was isolated. Branded remediation text was isolated to
this one record. Stale researcher attribution was not: 50 of 80
records still carry 'Bawbel Security Research Team', far more than
this task's premise of one record missed by an already-complete
project-wide pass. Not fixed here per this task's own scope
instruction -- flagged as a separate, deliberate follow-up audit.
@chaksaray
chaksaray merged commit c494f8c into develop Aug 25, 2026
6 checks passed
@chaksaray
chaksaray deleted the fix/ave-00048-attribution-and-branding branch August 25, 2026 23:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant