Earlier quoted context omitted.
Yeah, it is their fault. I don't download "todesktop" (to-exploit), I download Cursor. Don't give 3rd parties push access to all your clients, that's crazy. How can this crappy startup build server sign a build for you? That's insane.
it blows me away that this is even a product. it's like a half day of dev time, and they don’t appear to have over-engineered it or even done basic things given the exploit here.
How to gain code execution on hundreds of millions of people and popular apps
171–180 of 350 posts
Re: How to gain code execution on hundreds of millions of people and popular apps
#172The cat is cute but I'd rather not have it running in front of the text while I'm trying to read and use my cursor.
Re: How to gain code execution on hundreds of millions of people and popular apps
#173This website loads extremely fast wow
Re: How to gain code execution on hundreds of millions of people and popular apps
#174My goodness. So much third-party risk upon risk and lots of external services opening up this massive attack surface and introducing this RCE vulnerability. From an Electron bundler service, to sourcemap extraction and now an exposed package.json with the container keys to deploy any app update to anyone's machine. This isn't the only one, the other day Claude CLI got a full source code leak via the same method from…
Re: How to gain code execution on hundreds of millions of people and popular apps
#175> security incidents happen all the time Do they have to? Isn't this notion making developers sloppy?
Re: How to gain code execution on hundreds of millions of people and popular apps
#176My goodness. So much third-party risk upon risk and lots of external services opening up this massive attack surface and introducing this RCE vulnerability. From an Electron bundler service, to sourcemap extraction and now an exposed package.json with the container keys to deploy any app update to anyone's machine. This isn't the only one, the other day Claude CLI got a full source code leak via the same method from…
Blaming Js/Ts is ridiculous. All those same problems exist in all environments. Js/Ts is the biggest so it gets the most attention but if you think it's different in any other environment you're fooling yourself.
Re: How to gain code execution on hundreds of millions of people and popular apps
#177Question/idea: can't GitHub use LLMs to periodically scan the code for vulnerabilities like this and inform the repo owner? They can even charge for it ;)
Re: How to gain code execution on hundreds of millions of people and popular apps
#178Question/idea: can't GitHub use LLMs to periodically scan the code for vulnerabilities like this and inform the repo owner? They can even charge for it ;)
Re: How to gain code execution on hundreds of millions of people and popular apps
#179Bit too hyperbolic or whatever... Otherwise thrilling read!
Re: How to gain code execution on hundreds of millions of people and popular apps
#1802. Release your product.