There appears to be a new trend of using (AI) tools to find already patched security vulnerabilities in open source tools.
Example:
- one by Facebook: oss-security - CVE-2025-27363: out of bounds write in FreeType <= 2.13.0
- one by a person: Encountered a signed integer overflow in src/cff/cf2intrp.c (#1312) · Issues · FreeType / FreeType · GitLab
I found this interesting and thought I’d share, not really actionable.