logoalt Hacker News

gchamonlivetoday at 12:17 AM1 replyview on HN

In the age of AI, carrot disclosure is potentially a full disclosure with extra steps. I'm no security expert, but with the context provided, the forgejo codebase and the outline of the redacted script, I think there is a good chance I could use codex to crunch through the vuln chain and reproduce the script.


Replies

nine_ktoday at 1:13 AM

Where's the vuln chain? Is it even obvious which APIs have been called?