Findings
Bugs ChipLab's AI agents found in open-source hardware. One agent finds and documents each bug against the specification; a different agent reproduces it from scratch before it is reported to the project's maintainers.
- Reports filed
- 24 6 public, 18 via security teams
- Projects (public reports)
- 3
- Fixed upstream
- 0
Each report carries a CLAB reference; this page links to it as
findings.html#clab-2026-NNN. Security-relevant findings go through each project's private
disclosure channels; they are counted above but listed here only once the fix is public. Updated 10 October 2026, 07:02 UTC.
| Ref | Project | Finding | Status | Filed |
|---|---|---|---|---|
| CLAB-2026-001 | olofk/serv | Reading mie clears MTIE (csrr / csrrs / csrrc with x0 disables timer interrupts) olofk/serv/issues/173 | Open | 2026-10-08 |
| (fix for 001) | olofk/serv | serv_csr: Return MTIE when reading mie olofk/serv/pull/174 | Open | 2026-10-09 |
| CLAB-2026-024 | Wren6991/Hazard3 | [dm] sbcs.sbaccess resets to 0 (8-bit) instead of 2 (32-bit) when System Bus Access is enabled Wren6991/Hazard3/issues/50 | Open | 2026-10-09 |
| CLAB-2026-023 | Wren6991/Hazard3 | [dm] A host write to data0 while an abstract command is busy changes data0 (spec: value unchanged) Wren6991/Hazard3/issues/51 | Open | 2026-10-09 |
| CLAB-2026-022 | Wren6991/Hazard3 | [alu] amominu.w / amomaxu.w store the signed min/max when Zbb is disabled (default A=1, Zbb=0) Wren6991/Hazard3/issues/52 | Open | 2026-10-09 |
| CLAB-2026-026 | stnolting/neorv32 | [slink] RX_FULL / TX_EMPTY / TX_NFULL interrupt enables are at bits 18/19/21 in the RTL but 17/18/19 in the datasheet and neorv32_slink.h stnolting/neorv32/issues/1662 | Open | 2026-10-09 |
| CLAB-2026-027 | stnolting/neorv32 | [dma] Byte-to-word transfer writes the byte replicated (0x34343434) instead of zero-extended (0x00000034) stnolting/neorv32/issues/1663 | Open | 2026-10-09 |