logoalt Hacker News

Animatsyesterday at 4:21 AM1 replyview on HN

If it lets you do an arbitrary HTTP GET on a URL sent as a parameter to the main URL, you've escaped the sandbox rules.


Replies

simonwyesterday at 4:24 AM

How do you then use GET requests to create a malicious dataset package and publish that to Hugging Face in order to exploit their package building infrastructure?

show 1 reply