We want to address attribution oversights in several of our CVE disclosures and properly credit the original researchers for those findings.
Earlier this year, we used our AI SAST tool to scan GitHub and find vulnerabilities in open-source repositories. For all findings by Gecko, we worked directly with the maintainers to develop and release fixes. We've since learned that some of our findings had already been discovered first by other researchers on separate bug bounty platforms with one already having a CVE assigned, but no public fix released. At the time of our disclosures, neither we nor the maintainers were aware of any prior reports. We scanned the latest versions of code and only checked GitHub and CNA advisories, not different bounty platforms, which was an oversight on our part.