logoalt Hacker News

hsbauauvhabzbtoday at 9:02 AM1 replyview on HN

Ironically typing ‘make sure my server is secure’ into an LLM either wasn’t done, or missed it until now.


Replies

wongarsutoday at 10:50 AM

The posted page has an entire section titled "Why didn't Mythos find this?"

tl;dr: the bug spans three components in different code bases that when looked at in isolation each do reasonable things. The bug is in the interaction, in the assumed properties of the value that eventually gets exposed as request.url.path. That was apparently too subtle for current Anthropic models to spot

show 1 reply