5 ms·
AISLE Discovers 38 CVEs in OpenEMR Healthcare Software
- asah 5mo agoonly 38 CVEs - that's pretty good! ...so far !
- simonw 5mo ago"The values passed to _sort were concatenated directly into SQL ORDER BY clauses with no validation" - sounds to me like this project had some low-hanging fruit! Looks like every single one of the 38 vulnerabilities were either SQL injection, XSS, path traversal or "Insecure Direct Object Reference" aka failing to check the caller was allowed to access the record. This is actually a pretty good example of the value of AI security scanners - even really strong development teams still occasionally let bugs like this slip through, having an AI scanner that can spot them feels worthwhile to me.
- hilariously 5mo agoHonestly those all sound like common linters could find things like string concatenation.
- Taters91 5mo agoThese kind of checks were available without AI.
- deleted 5mo ago[deleted]
- sheikhnbake 5mo agoMath is doable without a calculator
- happytoexplain 5mo agoThe headline is "AI uncovers...", implying that the standard static analyzers used by basically everybody didn't catch them.
- serf 5mo agoisn't this just sort of turning chicken-or-egg? if an AI uses static analyzers to do work ,is it the tool or the ai ? if AI is using grep to do the work, is it the AI or grep? I mean essentially all agent work boils down to "cat or grep?"
- positron26 5mo agoWas the human labor?
- RA_Fisher 5mo agoAI gives us a means of leverage. We can do more with less. production = f(labor, capital, technology) + eps
- krainboltgreene 5mo agoThis always comes up and the only thing I can think is: Doesn't Google make like 10B a quarter in profit from GCP alone? Did we really need a cheaper SQL injection checker?
- gowld 5mo agoI think SQL Injection detectors were pretty mature even before the "AI" version?
- EGreg 5mo ago“even really strong development teams” One would think a single really strong developer, let alone a team, would look for interpolation in strings fed to RDBMS?
- tmoertel 5mo ago> Looks like every single one of the 38 vulnerabilities were either SQL injection, XSS, path traversal or "Insecure Direct Object Reference" aka failing to check the caller was allowed to access the record. Seems like code review against a checklist of the most common vulnerabilities would have prevented these problems. So I guess there are two takeaways here: First, AI scanners are useful for catching security problems your team has overlooked. Second, maintaining a checklist of the most-common vulnerabilities and using it during code review is likely to not only prevent most of the problems that AI is likely to catch, but also show your development team many of their security blind spots at review time and teach them how to light those areas. That is, the team learns how to avoid creating those security mistakes in the first place.
- dgb23 5mo agoBut by not having a checklist you avoid that your blind spots get exposed.
- tmoertel 5mo agoWhy would you want to prevent your development team from learning about their blind spots?
- capiki 5mo agoWhat about having the checklist and having an AI tool use it to catch things at review time (or even development time)?
- gchamonlive 5mo agoIsn't this something SonarQube catches?
- webXL 5mo agoYes. Isn't this something code review catches? :)
- positron26 5mo agoPresuming there is an infinite pool of programmers who tirelessly work for a low price?
- deleted 5mo ago[deleted]
- gchamonlive 5mo agoI'm really curious what's your line of thinking here. Could you elaborate?
- happytoexplain 5mo agoSometimes, but not nearly as reliably as a static analyzer. But I'm assuming the unstated point you are sarcastically implying is "you don't need SonarQube" - maybe you're trying to say something else.
- gchamonlive 5mo agoWebXL makes no sense, because that's comparing oranges to apples.
- camdenreslink 5mo agoI don't think strong development teams are still letting SQL injection vulnerabilities through by manually concatenating strings to build queries with user-provided data. Not in the year 2026.
- simonw 5mo agoGood frameworks can protect against SQL injection and XSS (through default escaping of output variables) but protecting against insecure direct object access is a lot harder.
- voxic11 5mo agoKeep in mind this project is a 25 year old PHP application.
- zarzavat 5mo agoThat actually makes it more confusing since a 25 year old PHP application is exactly where you'd expect to find SQL injection vulnerabilities. If I were in charge of a 25 year old PHP application, tracking down every SQL query and converting it to a safe form would high on my list of priorities. You don't need AI for that, just ripgrep and a basic amount of care for your users.
- otabdeveloper4 5mo agoReplacing/automating manual ripgrep is a top-1 use case for AI though.
- pseudalopex 5mo agoTheir point was a competent team would have done this since 10 or 20 years I thought.
- whythismatters 5mo agoMost (proprietary) 25 year old PHP codebases I've seen are a huge mess riddled with issues, exuberant loc, mix of tabs and spaces and weird indentation, dry violations, slightly diverging code blocks copy-pasted all over the place, etc., etc. Resolving technical debt (let alone reviewing the "stuff that works" like SQL queries) is often low priority because it's tedious and does not create any "business value".
- gostsamo 5mo ago> This is actually a pretty good example of the value of AI security scanners Are you fuckin' serious? This would be caught with any self-respecting scanner even 5 years ago and with most educated juniors even earlier. I use AI every day, but I'm not deep enough in the dilulu to believe that everything above two brain cells should be a transformer.
- simonw 5mo agoWhich scanners catch insecure direct object access?
- nudpiedo 5mo agoThere are Static code analyzers which already would have detected that. And these were also automatic. Looks very likely that the team didn’t give a damn about top basic security and good practices. Like a house made of paper wouldn’t be an example of the insecurity of the construction industry.
- simonw 5mo agoWhich static code analyzers do you recommend?
- happytoexplain 5mo agoSonarQube is extremely common, but I'm sure there are many.
- Groxx 5mo ago>even really strong development teams still occasionally let bugs like this slip through agreed, though I think you'd be hard-pressed to find anyone who uses healthcare-related software professionally who thinks any "really strong development team" was involved in its creation.
- dflock 5mo agoNo one knows how many vulnerabilities there are in closed source medical record software - because we can't check. There are _probably_ loads though, because that medical software is super terrible in every way that we _can_ check.
- oatmeal1 5mo agoOr voting machines.
- mixedmath 5mo agoI wasn't aware that there were any public, commonly-used voting machines that we could check.
- 0xdeadbeefbabe 5mo agoSQL injection and XSS come up in dynamic analysis too.
- 1970-01-01 5mo agoIsn't anything closed-source by definition this? Why speak of the subset of closed-source medical record software when it's just the entire class of software?
- nradov 5mo agoWell the closed-source EHR applications that use NoSQL databases such as MUMPS (InterSystems Caché) probably don't have many SQL injection vulnerabilities.
- 0xdeadbeefbabe 5mo agoAlso the attackers may become hypochondriacs after reading too much medical stuff.
- 0123456789ABCDE 5mo agosomething i am missing in this area is education and services. if, during an automated code review, claude finds a vulnerability in a dependency, where should i direct it to share the findings? who would be willing to take the slop-report, and validate it? i've never done vulnerability disclosure, yet, with opus at max effort, i have found some security issues in popular frameworks/libraries i depend on. a proper report can't be one pass, it has to validate it's a real problem, but ask opus to do that and you run the risk of the api refusing the request, endangering your account status. you ask to do it anyway, and write a report and now, you're burning tokens on a report that's likely to be ignore, because slop. so i sit on this, and hope it doesn't hit me.
- 0123456789ABCDE 5mo agoi'd be happy to use an official skill for vulnerability reporting the skill would be manually triggered when vulnerabilities are found; do another pass for details; version, files, lines, then write a lightweight report and submit somewhere. anthropic could host this, or work with h1 to do that. when the models have extra capacity a process comes around and picks up these reports one by one, does another check, maybe with proof-of-concept, reports through proper channels.
- hedgehog 5mo agoIt often takes strong understanding of the upstream codebase and roadmap to write a good patch. It's easy enough to write a rough PoC and draft patch but getting all the way through the cycle takes up a bunch of time both from you and the maintainers (who are often already overloaded). My advice would be to draft a bunch privately, take one of the highest impact all the way through a deployed fix, and then plan based on what you learn. Some people's answer is to maintain private forks with automated fixes applied, with a periodic rebase on upstream.
- 0123456789ABCDE 5mo agoi'm well aware that a pull-request with a fix is a lot of work. i don't pretend to have the capacity to do this, with all the rest i have to attend to. it just doesn't sit well with me that, i am aware of something being broken, and not telling about it to someone who would otherwise want to know about it.
- giancarlostoro 5mo agoI've said it a few times, and I will keep saying it. Especially for the anti-AI crowd. Sure, you don't want it to write your code, fine, not bothered at all, but review your code for serious security flaws, and enhancing security audits? You definitely want AI there. I foresee the next few years we will see all sorts of companies, sites, and critical infrastructure being hacked. Heck, we're already seeing more and more of this. It's not going to end very well. If your company is sleeping on its cyber security, tomorrow isn't when you want to deal with it, but get on it before you can. I say this purely as a Software Engineer, not a security expert, but you have to consider hackers can, are, and will use AI against you. The Mexican government was hacked by people using Claude[0] this was apparently many government systems and services, all that PII for everyone in the country in these systems. Even if Claude somehow "patches" this, there's so many open source models out there, and they get better every day. I've seen people fully reverse engineer programs from disassmebling their original code into compilable code in its original programmed language, Claude happily churning until it is fully translated, compiles and runs. Whatever your thoughts on AI are, if you aren't at least considering it for security auditing (or to enhance security auditing) you are sleeping at the wheel just waiting to be hacked by some teenager skiddie with AI. [0]: https://news.ycombinator.com/item?id=47280739 https://news.ycombinator.com/item?id=47280739
- captainkrtek 5mo agoAmen to this. I've bounced back and forth on my feelings for AI and have landed in the realm of: - there are certain things it is exceptional at that humans cannot replicate. - there are certain things I do not want to use it for. And review falls squarely in that first category. Similarly, it is exceptional at working through "low hanging fruit" type problems such as spotting inefficiencies, analyzing a profile to find flaws in software, etc.
- dgb23 5mo agoIt seems to me that this sort of work is a usecase that’s actually very fitting use case for LLM agents and the like. Because they can be trained and tuned to find commonly known vulnerability patterns. Here, something that looks like the thing is a strong signal, as long as the probability is high enough to be useful. Remember Netflix‘ chaos monkey?
- Exoristos 5mo agoNow do Epic.
- DANmode 5mo agoIs there a process server at your place yet?
- jjwiseman 5mo agoThe Aisle "the moat is the system, not the model" blog post comparing Mythos' results to their system's was misleading, and seemed to be an attempt to ride the coattails of attention on Mythos. It was of low enough quality that I'd want to see more details of exactly how these vulnerabilities were found.
- breezedream 5mo agoIt’s marketing content. This is a fundamental aspect of cybersecurity business. Fused marketing with research. Seems HN is susceptible to it.
- mbesto 5mo agoWhat's probably WAY worse than this is that most healthcare providers running OpenEMR are likely on older versions of OpenEMR where CVEs are already detected.
- doctorpangloss 5mo agoNobody uses OpenEMR. No chance. They are lying about their numbers.
- whartung 5mo agoI can't speak to OpenEMR, but OpenMRS is popular overseas, and has done a lot of work in Africa. OpenEMR may be in similar spaces.
- tecleandor 5mo agoWell, it's not popular maybe on bigger hospitals, but back in the day I think it was relatively popular on smaller practices even on the US. I don't know if it has lost traction (or not) with the popularization of cloud services, I'm not super up to date...
- ranger_danger 5mo ago> used by over 100,000 medical providers serving more than 200 million patients across 34 languages Interesting... I have been working with many different EHR platforms across the country for the last 15 years and I have never heard of OpenEMR before, or any open-source platform for that matter.
- rustyhancock 5mo agoI think we'll see a lot more of this (and it's a good thing). Automation doesn't usually replace humans it just hikes up the floor. I.e. nearly all of these (most in general?) bugs will be spotted quickly by a train eye. But it's hard to get trained eyes on code all the time. AI will catch all the low hanging fruit. What's great about this it seems mostly low hanging I.e. even basic AI will help people patch holes.
- hereme888 5mo agoOpenEMR? Used by some missionary doctor in remote Afghanistan?
- floatrock 5mo agoRight. You're not a real medical group unless you go through an 18-month RFP procurement cycle including being wined and dined by the Epic rep who already knows they're gonna get your $50MM wallet because they're golf buddies with your CEO and already embedded with all your labs. God forbid anyone practicing Real Medicine tries to go the OSS route, medicine is too complicated for something like that.
- jabl 5mo ago$50M? Pfft. The regional health service provider over here has spent close to a billion € migrating to Epic over the past decade. The feedback has been so devastating they're apparently now considering starting over from scratch. Love seeing the consultants lighting my tax money on fire like that.
- DANmode 5mo agoRemote Afghanistan has 100,000 medical providers working in 34 languages?
- hereme888 5mo ago34 dialects? The numbers are here and there, you know.
- motoxpro 5mo agoA better headline would be "AI finds mistakes made by human" It's not that it's doing something novel, every single person in this thread has made mistakes, and big ones, not because we aren't trying, it just happens. AI helps find some mistakes, not all, not everytime, not without effort, not without slop/false positives, just some mistakes. Thats a very good thing.
- demorro 5mo agoCompletely normal and expected. People thinking that this isn't the case everywhere need a reality check. Most software is riddled with obvious security issues. If we can remediate them with AI, great, but don't be thinking that this is something that we could only have dealt with with AI. Enough attention and prioritization of these issues would also have sorted it. Ask yourself if we weren't currently in an era of AI-focus and AI was just another boring tool, if we would be bothering to do this sort of thing. Loads of us still aren't bothering with basic static analysis.
- unshavedyak 5mo agoHeck, unless AI gets absurdly cheap - i feel like even this will be temporary. To your point, we don't do that now because it's not fun and no one broadly finances this sort of thing. However AI costs money, so why are we spending it now? I imagine it's just a temporary spend to explore the space, show what models are capable of, further embed usage of AI for future rugpulls, etcetc. Point is unless it eventually becomes cheap enough that we all have this at home and can run SOTA analysis ourselves, this too will pass. I imagine it will get cheap enough fwiw, but.. yea.
- prerok 5mo agoPresumably now we also have exploits written by AI, so I guess security has to be one-upped now? Not that I expect companies to be more proactive now. I have been disillusioned of that long ago. With AI they could be at least a little bit more proactive, which I guess is a great selling point of AI to corporate.
- demorro 5mo agoAye. The "use boring tech" advice isn't just about technical stability. You need to guard yourself against eventual boredom and ecosystem decay. Hype and enthusiasm can mask how likely these systems we put in place are to actually be maintained or used in the long term. I'm sure that doesn't matter much to big tech folks seeking to fill that promotion packet though, or to executives seeking to demonstrate the overwhelming utility of this new income stream.
- muglug 5mo agoMost of these vulnerabilities could have been discovered much earlier had the same security researchers pointed a SAST tool at the codebase. I wrote an OSS PHP SAST tool 6 years ago, but it's suffered from industry neglect — most people only care about security after an incident, and PHP has enough magical behaviour that any tool needs to be tuned to how specific repositories behave. I agree there's a big opportunity for LLMs to take this work forward, filling in for a lack of human expertise.
- unethical_ban 5mo agoWhere can I learn more about SAST, and do you have a link to your tool? I stood up a Dokuwiki instance recently and had Qwen look through the codebase, and it didn't find anything critical. It identified "fragile patterns", though.
- muglug 5mo agoIt's Psalm — see the section on security analysis here: https://psalm.dev/docs/security_analysis/ https://psalm.dev/docs/security_analysis/
- zuzululu 5mo agoThis is the new trend that keeps me awake at night. It's that adversaries now have access to off the book inference and that they will be able to scan pretty much any widely used open source project and discover and exploit zero days. I think making it closed source offers a bit more security but will only buy time as it is possible to reverse engineer them with current closed source models with extreme ease. If you are sufficiently funded then you could benefit from the flip side of discovery but it looks bleak if you are a sole maintainer on a large project that is a dependency in many deployed instances without any revenue or donations, plus there is nobody digging deep enough to care or spend inference ( would your company spend the money on extra inference to is the question, more often than not) on both sides of the fence, we are going to see massive disruptions across the board. Cybersecurity is becoming a proof-of-work of sorts and the race is on. There might be unknown number of zero days being silently discovered and deployed, likely have an impact on the economics too, thus making the access far more widespread. I do wonder if this means our tech stacks will go back to being boring and simple as possible...you wouldn't hack a static html website being served on nginx would you?
- eithed 5mo agoIt's nothing new - even without LLMs you have automated tools that will try stuff to see if your application is vulnerable. You can abuse misconfigured nginx server. To be fair, to your point, LLMs are amazing pattern recognizers = this pattern it has seen in this codebase applies to that codebase so vulnerability is most likely; I'm unsure if they can "innovate" (still, recognizing patterns is enough); this pattern it has seen causes a crash, but I don't know if we're at the point where it can connect two and two together and use a set of unrelated code issues to, for example, exfiltrate credentials
- MattCruikshank 5mo agoEDIT: Looks like they did responsibly disclose - that's nice. I missed the single line at the bottom of the article. I'd prefer if an article like this opened with a paragraph about their conversation with the maintainers, and how all vulnerabilities have already been patched, etc. But I guess that's a personal preference. === Did they privately disclose these vulnerabilities to the developers and give them a reasonable amount of time to fix them, before they announced them to the world? Because, and I'm going to highlight, if someone exploits a CVE in an EMR, they can wreck havoc on actual real patient data, and can endanger health and lives. https://github.com/openemr/openemr/security https://github.com/openemr/openemr/security "Option 1 (preferred) : Report the vulnerability at this link. See Privately reporting a security vulnerability for instruction on doing this." Did they do that? Because if they didn't responsibly disclose, this sure seems like a hit job performed by someone who'd rather EMR software be closed source.
- 1970-01-01 5mo agoRTFA, Matt. Your answer is at the end of it.
- MattCruikshank 5mo agoHave you heard of the term, "bury the lede"? I'd love to see an opening paragraph like this one: "All discovered vulnerabilities have already been patched. We waited to publish this article until they were. Release 8.0.3 addresses all of them, and we advise updating as soon as possible. We waited until 95% of installs had already updated to that version."
- david_shaw 5mo agoWe'll see more of this, but this particular review is driven by marketing narrative. I'll explain what I mean: Back in 2010, as a security engineer, I also looked at OpenEMR. It was an absolute disaster, and was (and is) somewhat well-known as such. I found and published vulnerabilities very similar to these sixteen years ago. This is not exactly the Fort Knox of software. It makes sense for AISLE to demonstrate that they're able to find vulnerabilities here, but I'd love to see a side-by-side comparison of modern SAST and DAST reviews. I bet we'd find similar vulnerabilities.
- danaw 5mo agonow let's open source all healthcare systems so we can at least collectively improve these things rather than trusting companies like oracle to be good faith actors with equally acceptable security
- joshghent 5mo agoHad exactly the same sort of experience using AI to audit a code base we inherited recently at $dayJob. Spotted over 100 “security issue but after whittling them down via reproduction scripts and validating they were real CVE’s - that number was around 30. Even so - it was a huge win and something we wouldn’t have spotted. It’s something I’ve now codified into repowarden.dev
- dematz 5mo agoduffpkg's comment 2 years ago does not inspire great confidence in OpenEMR: https://news.ycombinator.com/item?id=40763424 https://news.ycombinator.com/item?id=40763424 >I was the main contributor and maintainer to OpenEMR about ~20 years ago and then decided it was irredeemable and started over with ClearHealth/HealthCloud. Shockingly some of my code code lives on (from PHP 3). I am reluctant to say don't use it but if you do please don't expose it to anything public, which sadly happens most of the time. There are some real problems that exist in that code base from a security and HIPAA perspective. Finding SQL injections etc is definitely valuable, but at the same time they did not hack Epic; the "100000 medical providers" number links to https://www.hhs.gov/sites/default/files/open-emr-sector-alert.pdf https://www.hhs.gov/sites/default/files/open-emr-sector-aler... which links open-emr.org/blog/openemr-is-proud-to-announce-seamless-support-for-telehealth/ which...404s. Per archive.org the source is something the CEO of now defunct lifemesh.ai said. "medical record software" makes it sound super serious, but again OpenEMR should not be taken as seriously as for instance Epic.
- caycep 5mo agohow healthy is the open source community around openEMR? I feel like by nature, it is decidedly more unsexy and less attractive for volunteers to work on. I work in healthcare, and PTSD from various EMRS have run so deep that working on an actual EMR is the most unappealing thing I can think of to tinker around with code....
- bobkb 5mo agoI had reviewed this application long ago to find tons of issues - not surprised many of it are now CVEs. I am also surprised that the product is still active.
- KaiserPro 5mo agoOk this is cool and that, but show me the prompts. Was this autonomous, as in "look at this repo and find me all the CVEs that could exist"? Or was it much more guided?