Contributions
Security fixes shipped
to real projects.
Every vulnerability Sebastion finds in open source gets a fix, not just a write-up. These are the projects we've contributed accepted security patches to.
5
Fixes Accepted
4
Projects
5
Case Studies
Projects
Accepted Fixes
Mergedskills
fix: prevent SQL injection in sql_manager.py (CWE-89)
SQL InjectionCWE-8921 Feb 2026
Mergedsummarize
fix: restrict daemon CORS to trusted origins (CWE-942)
CORS MisconfigurationCWE-94221 Feb 2026
Mergedsummarize
test: add CORS allowlist edge-case coverage
CORS Misconfiguration10 Mar 2026
Cherry-pickedhermes-agent
fix: prevent path traversal via .worktreeinclude entries
Path Traversal14 Mar 2026
Mergedgptme
fix: use --env-file for docker secrets instead of CLI args (CWE-214)
Information Exposure (CWE-214)CWE-21423 Mar 2026
This page updates automatically. Data sourced from GitHub via Sebastion's autonomous audit pipeline.