Dev earns first CVE: CVSS 8.8 memory corruption in Ghost, PoC built with MiniMax M3

DanielLockyer · x · 2026-10-02

DanielLockyer got his first CVE — a CVSS 8.8 memory corruption bug in Ghost. After reading about HEIF Heist's impact on libheif (bundled in libvips, bundled in sharp), he used MiniMax M3 to build a working PoC image and script that also abused loose file-extension logic to bypass MIME checks; the repro reliably crashes the container and may allow code execution.

Related event: Developer Lands First CVE by Mining Critical Ghost Bug with MiniMax M3(2 posts)→

Original post →

More from coding & agent

coding & agent channel →