logoalt Hacker News

mananaysiempretoday at 7:51 AM3 repliesview on HN

TL;DR: obj[key] with user-controlled key == "__proto__" is a gift that keeps on giving; buy our AI tool that will write subtle vulnerabilities like that which you yourself won’t catch in review but then it will also write some property-based tests that maybe will


Replies

fireflash38today at 10:51 AM

Don't forget you can use AI to turn a 50 word blog post into a 2,000 word one!

show 2 replies
toobulkehtoday at 6:29 PM

It also talks about using PBT and Randomness for some reason. This is clearly just a test value of a non-AI library written by a human.

My take away is “don’t write your own input tests, use a library”. The rest is AI-slip

show 1 reply
nslogtoday at 3:01 PM

Didn't react just have basically the same vuln

show 1 reply