Using Reasoning Models in AutoTriage
ID: c78b9eeb-9782-53c3-9e43-2230b5e0ae5a
STIX ID: report--c78b9eeb-9782-53c3-9e43-2230b5e0ae5a
Feed Name: Aikido Security's Blog
This report evaluates the use of reasoning language models in SAST AutoTriage, arguing they are overkill for most rules but significantly more effective for complex cases like JavaScript path traversal. It explains multiple path traversal patterns ("../", "..\", lone "..", and leading "/" with path.resolve()) and recommends robust remediation and triage checks — notably resolving and validating paths against a known base — while noting reasoning models can halve false positives for these edge cases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
