fix: AVE-2026-00048 attribution and remediation branding - #202
Merged
Merged
Conversation
…026-00048 researcher field still carried the deprecated team-name convention. Researched whether Cohen et al. (arXiv:2403.02817, cited in this record's own references) is the actual source of the delegation- inheritance mechanism before deciding attribution: read the full paper, it describes a self-replicating worm (Morris-II) propagating via RAG-based indirect prompt injection across GenAI applications, a related but structurally different problem, not sub-agent permission inheritance. A full-text search for delegation/sub-agent/inheritance/ trust-boundary language returns zero substantive matches. This is AVE's own synthesis of CWE-269/284 into the agentic delegation context; researcher corrected to Saray Chak, Cohen et al. stays cited as related context in references, unchanged. Also removes a Bawbel-branded product reference (bawbel-accept) from the remediation text, replaced with a generic, vendor-neutral time-bounded-grant control description. Checked the rest of the corpus for both patterns rather than assume this record was isolated. Branded remediation text was isolated to this one record. Stale researcher attribution was not: 50 of 80 records still carry 'Bawbel Security Research Team', far more than this task's premise of one record missed by an already-complete project-wide pass. Not fixed here per this task's own scope instruction -- flagged as a separate, deliberate follow-up audit.
This was referenced Aug 25, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two issues found on a record currently being read by an external OpenCRE contributor.
Researcher attribution: still had the deprecated
Bawbel Security Research Teamteam-name convention. Before fixing, read the full Cohen et al. paper (arXiv:2403.02817) cited in this record's own references, to check whether it's actually the source of the delegation-inheritance mechanism rather than defaulting either way. It isn't — the paper describes a self-replicating worm (Morris-II) propagating via RAG-based indirect prompt injection across GenAI applications, a related but structurally different problem. A full-text search for delegation/sub-agent/permission-inheritance/trust-boundary language returns zero substantive matches. This is AVE's own synthesis of CWE-269/284 into the agentic delegation context, soresearcheris corrected toSaray Chak; Cohen et al. stays cited inreferencesas related context, unchanged.Remediation branding: point 5 named a specific Bawbel product feature (
bawbel-accept). Replaced with a generic, vendor-neutral time-bounded-grant control description.Corpus-wide check (both patterns, not assumed isolated): branded remediation text was isolated to this one record. Stale researcher attribution was not — 50 of 80 records still carry
Bawbel Security Research Team, far more than this task's premise of a single record missed by an already-complete pass. Not fixed here, per this task's own scope instruction — flagging as a separate, deliberate follow-up audit rather than silently expanding this PR.