PT-2026-78153 · Undefined · Undefined
CVE-2026-73855
·
Published
2026-08-18
·
Updated
2026-08-18
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Full disclosure: I’m Atto’s solo developer.
A structured Hermes audit found a critical flaw in Atto’s live vote handling. I verified it, stopped the release, and fixed it last month in node v1.33. It is now CVE-2026-73855, rated CVSS 9.3.
Later, gpt-5.6-sol in Codex independently found the exact same flaw without my purpose-built audit workflow. It still missed several less severe findings that the structured audit caught.
The experience changed how I think about context, subagents, and AI security reviews:
Are native Codex subagents enough for large security reviews now, or do you still use an explicit task and evidence structure?
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined