Publication Type

Conference Proceeding Article

Version

publishedVersion

Publication Date

4-2026

Abstract

Vulnerability identifiers such as CVE, CWE, and GHSA are standardised references to known software security issues, yet their use in practice is not well understood. This paper compares vulnerability ID use in GitHub pull requests authored by autonomous agents, bots, and human developers. Using the AIDev pop dataset and an augmented set of pull requests from the same repositories, we analyse who mentions vulnerability identifiers and where they appear. Bots account for around 69.1% of all mentions, usually adding few identifiers in pull request descriptions, while human and agent mentions are rarer but span more locations. Qualitative analysis shows that bots mainly reference identifiers in automated dependency updates and audits, whereas humans and agents use them to support fixes, maintenance, and discussion.

Keywords

Agents, Bots, Software Security, Vulnerability Identifiers

Discipline

Information Security | Software Engineering

Research Areas

Intelligent Systems and Optimization

Areas of Excellence

Digital transformation

Publication

MSR '26: Proceedings of the 23rd International Conference on Mining Software Repositories, Rio de Janeiro, Brazil, April 13-14

First Page

994

Last Page

998

ISBN

9798400724749

Identifier

10.1145/3793302.3793616

Publisher

ACM

City or Country

New York

Additional URL

https://doi.org/10.1145/3793302.3793616

Share

COinS