Slacker News Slacker News logo featuring a lazy sloth with a folded newspaper hat
  • top
  • new
  • show
  • ask
  • jobs
Library

Comment by ikmckenz

8 months ago

Related: https://arstechnica.com/gadgets/2025/05/open-source-project-...

2 comments

ikmckenz

Reply

moyix  8 months ago

The main difference is that all of the vulnerabilities reported here are real, many quite critical (XXE, RCE, SQLi, etc.). To be fair there were definitely a lot of XSS, but the main reason for that is that it's a really common vulnerability.

  • ikmckenz  8 months ago

    All of them are real? You have a 100% rate of reports closed as valid?

Slacker News

Product

  • API Reference
  • Hacker News RSS
  • Source on GitHub

Community

  • Support Ukraine
  • Equal Justice Initiative
  • GiveWell Charities