Post #4169455
2026-07-28 17:20 UTC
Another LLM-generated security report e-mailed to me today concerning some code I didn't write but I maintain. Requires users to load invalid configuration files to exploit a buffer overrun.
I've been given 90 days to fix the problem. Note I don't get paid to work on open-source software. And users shouldn't be loading random invalid configuration files.
This is just like e-mail. When there is zero cost associated with sending out junk mail, then you guarantee that junk mail will continuously be sent out. #Darknet #YOLO #CVE
Replies (1)
-
@charette@mstdn.ca 2026-07-28 17:45
I'd be less annoyed if one or more of the following were true: If I was paid to maintain the Darknet/YOLO codebase.If the user had submitted a PR with the proposed fix, showing they were actually part of the Darknet/YOLO community and not someone scanning thousands of github repos looking for problems.If the report that was sent to me wasn't so obviously written by a LLM.