Publication Type
Conference Proceeding Article
Version
publishedVersion
Publication Date
4-2026
Abstract
Vulnerability identifiers such as CVE, CWE, and GHSA are standardised references to known software security issues, yet their use in practice is not well understood. This paper compares vulnerability ID use in GitHub pull requests authored by autonomous agents, bots, and human developers. Using the AIDev pop dataset and an augmented set of pull requests from the same repositories, we analyse who mentions vulnerability identifiers and where they appear. Bots account for around 69.1% of all mentions, usually adding few identifiers in pull request descriptions, while human and agent mentions are rarer but span more locations. Qualitative analysis shows that bots mainly reference identifiers in automated dependency updates and audits, whereas humans and agents use them to support fixes, maintenance, and discussion.
Keywords
Agents, Bots, Software Security, Vulnerability Identifiers
Discipline
Information Security | Software Engineering
Research Areas
Intelligent Systems and Optimization
Areas of Excellence
Digital transformation
Publication
MSR '26: Proceedings of the 23rd International Conference on Mining Software Repositories, Rio de Janeiro, Brazil, April 13-14
First Page
994
Last Page
998
ISBN
9798400724749
Identifier
10.1145/3793302.3793616
Publisher
ACM
City or Country
New York
Citation
ROOIJENDIJK, Pien; TREUDE, Christoph; and WESSEL, Mairieli.
Who said CVE? How vulnerability identifiers are mentioned by humans, bots, and agents in pull requests. (2026). MSR '26: Proceedings of the 23rd International Conference on Mining Software Repositories, Rio de Janeiro, Brazil, April 13-14. 994-998.
Available at: https://ink.library.smu.edu.sg/sis_research/11325
Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International License.
Additional URL
https://doi.org/10.1145/3793302.3793616