Hacker News new | ask | show | jobs
by gnyman 988 days ago
I thought so at first but then I remembered server side request forgery, SSRF

That's a bug class that is quite common but rarely leads to code exec or other issues (except in some cloud environments). If this is something that gives code exec after pointing curl at a malicious server it's going to be bad.