Comment by otabdeveloper4
5 days ago
You can give the LLM a bash without giving it the full /usr/bin.
That's been a trivially solved problem for decades.
5 days ago
You can give the LLM a bash without giving it the full /usr/bin.
That's been a trivially solved problem for decades.
That has been one of the most common exploits for decades.
And as a result it is the most hardened.
So how do you explain it still being in the "OWASP Top 10" and the "CWE Top 25 Most Dangerous Software Weaknesses"?
Yes, and also MCP does literally nothing to prevent these sorts of exploits.
Like I said, AI bros vibecoding slop because they literally have no clue what they're doing.