logoalt Hacker News

throw_me_uwuyesterday at 9:12 PM1 replyview on HN

WTF, they not just made unauthenticated RCE http endpoint, they also helpfully added CORS bypass for it... all in CLI tool? That silently starts http server??


Replies

Hamukoyesterday at 9:14 PM

I'm slightly surprised that the CORS policy wasn't just "*" considering how wide open the server itself was.

show 2 replies