logoalt Hacker News

simonwtoday at 3:31 AM3 repliesview on HN

I expect it must have been more than just an open redirect if it let the models then go on to execute a bunch of vulnerabilities against Hugging Face.


Replies

Animatstoday at 4:21 AM

If it lets you do an arbitrary HTTP GET on a URL sent as a parameter to the main URL, you've escaped the sandbox rules.

show 1 reply
joshkatoday at 8:59 AM

I wonder if it was this bug fixed july 14 in sonatype:

https://support.sonatype.com/hc/en-us/articles/5316501964136...

pure speculation here - no non public info

show 1 reply