Live data from Hacker News

Mythos Finds a Curl Vulnerability

daniel.haxx.se

291–298 of 298 posts

Re: Mythos Finds a Curl Vulnerability

#291

Earlier quoted context omitted.

Yes. That’s my main driver. What do you mean you can’t get it to work?

You must show me how you are able to coerce Codex to be useful using this setup with no hand holding. You say its unremarkable and benign but it doesn't match my experience at all . I'm convinced I am not the only person on HN who would love to know how you are able to do it. > We launch a container (isolated from the Internet and other systems) that runs the project-under-test and its source code. We then invoke Cla…

I quite literally do this almost exactly with GPT 5.4. Sometimes I give it a poke in a direction but it largely runs by itself.

I don’t know what to tell you. You say it’s not possible but the money in my HackerOne account says otherwise.

Re: Mythos Finds a Curl Vulnerability

#292

Earlier quoted context omitted.

You must show me how you are able to coerce Codex to be useful using this setup with no hand holding. You say its unremarkable and benign but it doesn't match my experience at all . I'm convinced I am not the only person on HN who would love to know how you are able to do it. > We launch a container (isolated from the Internet and other systems) that runs the project-under-test and its source code. We then invoke Cla…

I quite literally do this almost exactly with GPT 5.4. Sometimes I give it a poke in a direction but it largely runs by itself. I don’t know what to tell you. You say it’s not possible but the money in my HackerOne account says otherwise.

> I don’t know what to tell you. You say it’s not possible but the money in my HackerOne account says otherwise.

I haven't said it was impossible. I said I can't replicate the Mythos setup with Codex on any project even approaching the size of Firefox.

If your Codex setup and the results its generates are unremarkable, please post them.

Re: Mythos Finds a Curl Vulnerability

#293

Earlier quoted context omitted.

I quite literally do this almost exactly with GPT 5.4. Sometimes I give it a poke in a direction but it largely runs by itself. I don’t know what to tell you. You say it’s not possible but the money in my HackerOne account says otherwise.

> I don’t know what to tell you. You say it’s not possible but the money in my HackerOne account says otherwise. I haven't said it was impossible. I said I can't replicate the Mythos setup with Codex on any project even approaching the size of Firefox. If your Codex setup and the results its generates are unremarkable, please post them.

My codex setup is quite literally a single file that states a format I want my reports to be written in so that I can review them before submitting them. Sometimes I bother with the container setup, sometimes I don’t depending on the work.

This isn’t a matter of a harness, skill files, anything. This is just something that a model can do.

You have multiple people saying they’ve done it here. I can only assume you’re being facetious at this point.

Re: Mythos Finds a Curl Vulnerability

#294

I feel like, if it was a codebase without using any security analysis tools, there would have been some more significant findings - perhaps they can re-run it on an 18 month old commit and see how many it found that were subsequenty found and fixed? Anyway, I think the case that frontier and next-gen models will get increasingly adept at finding vulnerabilities and that those on the receiving end of those vulnerabili…

Unfortunately that doesn't help much. LLMs are really really good at digging up known vulns, so much so that they often falsely declare known vulns as new and novel ones.

They have the CVEs in their training data, know how to look up ossfuzz logs, etc.

Re: Mythos Finds a Curl Vulnerability

#295

Earlier quoted context omitted.

> I don’t know what to tell you. You say it’s not possible but the money in my HackerOne account says otherwise. I haven't said it was impossible. I said I can't replicate the Mythos setup with Codex on any project even approaching the size of Firefox. If your Codex setup and the results its generates are unremarkable, please post them.

My codex setup is quite literally a single file that states a format I want my reports to be written in so that I can review them before submitting them. Sometimes I bother with the container setup, sometimes I don’t depending on the work. This isn’t a matter of a harness, skill files, anything. This is just something that a model can do. You have multiple people saying they’ve done it here. I can only assume you’re…

You've now spent multiple days in this comment thread describing this as simple and unremarkable but refuse to share anything about it. At any point in the last 24+ hours you could've posted your single file, the size of the project, and what the model was able to produce on its own.

Must this information be protected or is its unremarkable?

Re: Mythos Finds a Curl Vulnerability

#296
post #282
post #280

Earlier quoted context omitted.

Is not the selling of the model, that it is as capable as anyone and everyone? > Claude Mythos is Anthropic's most specialized model, trained exclusively on security research, vulnerability disclosures, and attack pattern literature. Its reasoning reflects how the world's best security researchers think. [0] [0] https://mythosvulnerabilityscanner.com/what-is-claude-mythos

Even if I was selling the model, which I am not, it still does not follow that you can judge that on a single run, given that no security researchers have found all of these bugs on their own in a short amount of time either.

Okay, to respin this - Daniel doesn't say that curl is secure-enough. Half the point of the talks this year, is there has been an uptick in detecting security bugs, not a downturn. And here's some graphs. [0]

> Given the look of these graphs I don’t think we are close to zero bugs yet. These two curves do not seem to even start to fall yet.

If the author thinks there is more to find, then the soil probably isn't dry.

But, from the author's mouth:

> My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing. [1]

[0] https://daniel.haxx.se/blog/2026/04/30/approaching-zero-bugs...

[1] https://mastodon.social/@bagder/116554460442650929

Re: Mythos Finds a Curl Vulnerability

#297
post #80

Earlier quoted context omitted.

Curl is currently receiving a record number of high-quality bug/vuln reports (a rather sharp change from the earlier slop inundation), so it’s not like there’s nothing to find. Many or most of these are presumably found by human experts assisted by AI tools, but if Mythos were truly revolutionary, it should be able to find such issues on its own. https://daniel.haxx.se/blog/2026/04/22/high-quality-chaos/ , linked fro…

Is there a list of infrastructure that has received this kind of focus? Clearly people are looking at the linux kernel, hopefully openssl?

From article:

> I did a quick unscientific poll on Mastodon to see if other Open Source projects see the same trends and man, do they! Friends from the following projects confirmed that they too see this trend. Of course the exact numbers and volumes vary, but it shows its not unique to any specific project.

> Apache httpd, BIND, curl, Django, Elasticsearch Python client, Firefox, git, glibc, GnuTLS, GStreamer, Haproxy, Immich, libssh, libtiff, Linux kernel, OpenLDAP, PowerDNS, python, Prometheus, Ruby, Sequoia PGP, strongSwan, Temporal, Unbound, urllib3, Vikunja, Wireshark, wolfSSL, …

Post reply on HN