Dev earns first CVE: CVSS 8.8 memory corruption in Ghost, PoC built with MiniMax M3
DanielLockyer · x · 2026-10-02
DanielLockyer got his first CVE — a CVSS 8.8 memory corruption bug in Ghost. After reading about HEIF Heist's impact on libheif (bundled in libvips, bundled in sharp), he used MiniMax M3 to build a working PoC image and script that also abused loose file-extension logic to bypass MIME checks; the repro reliably crashes the container and may allow code execution.
Related event: Developer Lands First CVE by Mining Critical Ghost Bug with MiniMax M3(2 posts)→
More from coding & agent
- Microsoft paper: coding agent optimizing prompts from logs beats GEPA at ~$1.60 — rohanpaul_ai · 2026-10-02
- Stop reaching for the biggest model: a cost-efficient Cursor/Codex setup with GPT-6.1 Sol — chiliraupe · 2026-10-02
- Dot isn't better than Codex or Claude Code — it's a different, undervalued take on OpenClaw/Hermes — gabrielchua · 2026-10-02
- Engineering.com parent Arrowfly launches year-round AI for Engineers initiative amid vibe-CAD era — burhop · 2026-10-02
- Run Fewer Agents: exe.dev argues task management is a band-aid, proposes fast models for human comms — sull · 2026-10-02
- Developer gives an AI agent $1,000 to run a live-streamed hedge fund — kleffew94 · 2026-10-02