HackerOne Discovers Critical RCE Vulnerability Using AI

HackerOne Discovers Critical RCE Vulnerability Using AI

First seen 2 Sep 2026, 19:43 UTC Computerweeklywww.hackerone.com 42.9

Article Content

Browse articles
ThreatCluster

HackerOne has identified and patched a critical remote code execution (RCE) vulnerability in its production environment, which was detected by Anthropic's Claude Mythos 5 AI model during a 30-day experiment under Project Glasswing. The vulnerability stemmed from three individually safe code changes that, when combined, created a significant risk. Although deployment conditions prevented exploitation, a change could have made it reachable. The flaw was characterized as a compositional risk, where safe changes interact over time to create vulnerabilities. HackerOne's chief product officer noted that traditional code reviews are blind to this type of risk. Following the discovery, HackerOne ran further experiments and concluded that AI models are identifying more sophisticated vulnerabilities, but the rapid generation of findings could lead to bottlenecks in validation and remediation. The company emphasized the need for new approaches to manage these findings effectively.

Key Points: • HackerOne discovered a critical RCE vulnerability using AI in its production environment. • The vulnerability arose from three safe code changes that created a compositional risk. • AI models are finding more sophisticated vulnerabilities faster than human teams can validate.

Timeline

2026-07-01
HackerOne initiates Project Glasswing
HackerOne began a 30-day experiment applying Claude Mythos 5 AI to its codebase.
www.hackerone.com
2026-09-02
Critical RCE vulnerability discovered
Mythos surfaced a critical RCE vulnerability during its first run against HackerOne's codebase.
www.hackerone.com
2026-09-02
Vulnerability patched
HackerOne remediated the RCE vulnerability within 48 hours of discovery.
Computerweekly