← Back to context

Comment by mr_mitm

4 hours ago

It's a zero day in some caching proxy who may not have had that threat model in mind. I guess its primary purpose is caching packages, not restricting internet access.

That's a far cry from finding a zero day in a hypervisor or even Docker, which OpenAI conveniently left out in their first statement by simply calling it a "sandbox".

That is the threat model, that is supposed to be safe isolated access in a vpc that isolated applications can access but it has external access.