Hacker News new | ask | show | jobs
by throw_me_uwu 156 days ago
WTF, they not just made unauthenticated RCE http endpoint, they also helpfully added CORS bypass for it... all in CLI tool? That silently starts http server??
4 comments

Someone tell the AI labs to stop training on tutorial code.
I'm slightly surprised that the CORS policy wasn't just "*" considering how wide open the server itself was.
It seems like it was prior to 1.0.216?
Just run it in a sandbox, bro.
It’s a vibe, bro.