CVE-Bench: testing LLM agents on real-world vulnerability patches
A recent evaluation of AI models for fixing security vulnerabilities revealed mixed results. The CVE-Bench benchmark tested five models on 20 real-world CVEs, finding that no model consistently resolved vulnerabilities. The best-performing model achieved a 60% success rate under optimal conditions, highlighting the challenges AI faces in this domain.
- ▪The CVE-Bench benchmark was created to assess AI models' ability to fix real-world security vulnerabilities.
- ▪Five models were tested on 20 CVEs, with the highest success rate being 60% under the best conditions.
- ▪The study identified structured failure modes in the models, such as wrong-search drift and budget exhaustion.
2 outlets in our directory ran this story, first to last over 12 hours. All of the coverage we found sits in one bucket: centre. That one-sidedness is itself worth noticing.
Hacker News (AI / LLM) files mainly under ai. We currently carry 3,266 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | Github |
| Canonical URL | https://giovannigatti.github.io/cve-bench/ |
| Publication time | Fri, 29 May 2026 19:28:55 +0000 |
| Retrieval time | 2026-05-29T19:45:02.813Z |
| Last seen | 2026-05-29T19:45:02.813Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | 0bgwOYaa--fg · 2 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
I Tested Whether AI Can Fix Security Vulnerabilities. Well, It's Complicated. ~15 min read Correction (2026-05-28): Five security tests in the original benchmark were found to reject valid alternative fixes that nonetheless addressed the reported vulnerability. Results were recalculated after correcting the tests. Solve rates increased by 3–7 points per model; the ranking order is unchanged, but cross-family pairwise comparisons that previously fell short of significance now cross α = 0.05 under McNemar with continuity correction. All affected numbers and statistical conclusions in this post have been updated.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Github.