GlobaLeaks Says 29 Vulnerabilities Fixed After AI-Assisted Audit
GlobaLeaks published an independent AI-assisted source-code audit on July 30, 2026 that identified 29 confirmed vulnerabilities, 12 denial-of-service issues and 42 hardening recommendations. The organization said two findings were High severity, none was critical, and all identified issues had been addressed. ISGroup reported about $3,140 in model API costs before human validation.
GlobaLeaks published the results of an independent AI-assisted source-code audit on July 30, 2026. The review identified 29 confirmed vulnerabilities, 12 denial-of-service issues and 42 hardening recommendations, according to GlobaLeaks and ISGroup, the firm that conducted the assessment.
The review ran from June 1 through June 30 and examined a development snapshot captured during an intensive hardening cycle. GlobaLeaks said most findings were Low or Informational, two were High severity and none was critical. The confirmed issues involved account protection, whistleblower anonymity safeguards, tenant isolation, audit-log completeness and service availability under specific conditions.
GlobaLeaks said all identified issues had since been addressed. Remediation of the confirmed vulnerabilities began with version 5.0.96, released June 24, and the organization identified version 5.0.99 as the latest stable release at publication.
What the audit cost
ISGroup reported approximately $3,140 in model API calls, or about $77 per confirmed finding before human validation. Its account says the highest-reasoning model consumed 62% of the budget while processing only 7% of the tokens, with less expensive models handling most of the broad code-reading volume.
Security Affairs reported that the campaign produced 110 triaged records in total
the 29 confirmed vulnerabilities, 12 denial-of-service issues, 42 hardening recommendations and 27 retained non-findings. It also emphasized that model outputs were treated as hypotheses until human reviewers traced them through the code, reproduced issues where needed and assessed practical impact.
The engineering takeaway
The evidence supports a narrower conclusion than autonomous vulnerability discovery. The workflow combined large-scale model-assisted reading with expert validation, severity assessment and remediation. It does not show that an LLM independently found every issue or that AI review can replace penetration testing.
For security teams, the practical change is the falling cost of broad codebase triage. That can make repeated review more feasible, but exploitability testing, false-positive filtering, patch verification and conventional security controls remain necessary, especially for software protecting anonymity or multi-tenant boundaries.
Key Points
- 1GlobaLeaks reported 29 confirmed vulnerabilities, 12 denial-of-service issues and 42 hardening recommendations, with two High-severity findings and no critical issues.
- 2ISGroup reported about $3,140 in model API costs, while human reviewers still validated candidates and assessed practical impact.
- 3The case shows cheaper broad code triage, not autonomous security assurance; exploit validation and remediation verification remain essential.
Scoring Rationale
The assessment is a concrete, current example of model-assisted source-code review on a mature security-sensitive open-source platform. Its disclosed costs and human-validation workflow are useful to application-security teams, though it is not a broadly released product or reproducible benchmark.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
