Dev Finds First CVE in Ghost: CVSS 8.8 Memory Bug, PoC Built by MiniMax M3
DanielLockyer · x · 2026-10-02
Developer Daniel Lockyer reports landing his first CVE: a CVSS 8.8 memory corruption bug in Ghost.
- The lead came from last week's HEIF Heist vulnerability affecting libheif, which is bundled in libvips, which in turn is bundled in sharp, a popular Node.js image processing library. Patches exist, but users must update the dependency themselves.
- To reproduce it, he had MiniMax M3 build a working PoC image file and script that reliably crashes the container, with possible room for code execution.
- He calls it a fun example of what AI can now do.
Related event: Developer Lands First CVE by Mining Critical Ghost Bug with MiniMax M3(2 posts)→
More from coding & agent
- Surrendering to Claude Code's permission prompts: granting Bash(*) to all — Daniel_Farinax · 2026-10-02
- Prime Intellect ships full post-training stack as Extropic runs custom RL with it — beffjezos · 2026-10-02
- Build an agent that remembers with Agent Platform Memory Bank — rseroter · 2026-10-02
- 8 Open-Source AI Agent Tools: From Computer-Use to Web Scraping — Aiden_Tech_Ai · 2026-10-02
- Claude Code 2.1.287 is about to be released — ClaudeCodeLog · 2026-10-02
- Claude Code creator uses "opponent" sub-agents to cross-check each other's work — every · 2026-10-02