Visa has released an open-source framework that uses AI agents to discover, verify, remediate and validate software vulnerabilities.
Visa has open-sourced its Visa Vulnerability Agentic Harness (VVAH), a model-agnostic framework designed to help security teams use AI for vulnerability discovery and remediation. The framework, developed from learnings from Anthropic’s Project Glasswing, allows organisations to inspect, adapt and contribute to the code rather than relying on a closed security platform.
VVAH uses a multi-stage workflow to analyse software and identify potential attack paths. Its discovery pipeline maps the attack surface, performs deeper analysis and adversarial verification, and then produces structured vulnerability reports. The repository supports outputs in formats including Markdown and SARIF, allowing findings to be incorporated into existing security workflows.
The framework goes beyond vulnerability detection by supporting remediation and validation. After a vulnerability is identified, the system can assist with developing and validating fixes, while security and engineering teams remain responsible for reviewing findings, assessing severity and approving remediation paths. Visa describes this approach as using AI to accelerate security work while retaining human oversight at critical decision points.
VVAH is designed to work with different AI models rather than being tied to a single model provider. Visa has also expanded the framework to support additional stages for remediation and validation, with the company reporting that some vulnerability-resolution workflows have been reduced from weeks to hours. Since its open-source release in June 2026, Visa says the project has been downloaded by tens of thousands of developers globally.
The project is available through Visa’s GitHub repository, giving security researchers and developers access to the implementation and an opportunity to adapt it to their own environments. Visa is also contributing VVAH to the Open Secure AI Alliance and collaborating through Project Lightwell to support security across open-source software. The release positions VVAH as an open framework for experimenting with AI-assisted vulnerability management as security teams face increasingly automated threats.















































































