2 ms·
Related: https://arstechnica.com/gadgets/2025/05/open-source-project-curl-is-sick-of-users-submitting-ai-slop-vulnerabilities/ https://arstechnica.com/gadgets/2
by ikmckenz 1y ago
Related: https://arstechnica.com/gadgets/2025/05/open-source-project-curl-is-sick-of-users-submitting-ai-slop-vulnerabilities/ https://arstechnica.com/gadgets/2025/05/open-source-project-...
- moyix 1y agoThe main difference is that all of the vulnerabilities reported here are real, many quite critical (XXE, RCE, SQLi, etc.). To be fair there were definitely a lot of XSS, but the main reason for that is that it's a really common vulnerability.
- ikmckenz 1y agoAll of them are real? You have a 100% rate of reports closed as valid?