Aeon AI Risk Management

Authorized AI security research, disclosed responsibly.

Aeon conducts frontier-level defensive and authorized offensive vulnerability research, then responsibly discloses confirmed findings through coordinated security channels before public naming. The validated aggregate covers 101 authorization vulnerabilities across 60 open-source AI and infrastructure projects, while the separate public track record contains four patched advisories and two assigned CVEs.

Questions this page answers

What can Aeon say publicly about its security research?
Aeon's owned-lab, AI-driven, human-reviewed pipeline found 101 authorization vulnerabilities across 60 open-source AI and infrastructure projects, including 4 Critical and 32 High findings. Its separate verified public record includes four patched security advisories and two assigned CVEs.
How does the research map to CyberGuard?
The dominant finding classes map to Access, Execute, and Leak: authorization and tenant boundaries, MCP and tool command boundaries, and data-path, SSRF, PII, secret, or retrieval exposure.
What should not be claimed publicly?
Do not name private, unpublished, or unpatched records. Do not describe the awarded bounty as paid while payment receipt remains pending. Aeon reports vulnerabilities, while independent CVE Numbering Authorities assign CVE identifiers.

Research principles

Authorized-only, whitehat, evidence-driven, non-destructive testing with coordinated disclosure and human expert review. Offensive capability is used only in approved scopes, owned labs, and responsible disclosure workflows.

Validated research record

101 authorization findings across 60 open-source projects, including 4 Critical, 32 High, and 92 broken access-control findings. Every finding was responsibly disclosed with a code-level fix.

Access

Authorization failures, BOLA, IDOR, tenant isolation, role boundaries, RAG document access, model-platform objects, and connector permissions.

Execute

MCP command boundaries, tool parameter handling, command injection, unsafe workflow actions, release gates, and permission-to-action gaps.

Leak

SSRF, fileserver and path-boundary issues, data-path exposure, PII enumeration, unsafe retrieval, secret handling, and evidence leakage.

Disclosure status

The frozen aggregate records 34 disclosure records across 33 projects, with 25 awaiting triage, 5 confirmed, accepted, or public outcomes, and 4 closed by duplicate or program-scope controls.

Verified public record

Four coordinated disclosure records are public and patched: CVE-2026-15015, CVE-2026-70436 / SECURITY-3907, GHSA-vg83-hcp4-5qcc, and GHSA-4rm9-rfp2-j39q. Two have assigned CVEs.