Researcher uses MiniMax M3 to build PoC, lands CVSS 8.8 memory-corruption CVE in Ghost
DanielLockyer · x · 2026-10-02
Security researcher Daniel Lockyer earned his first CVE: a CVSS 8.8 memory corruption bug in the image processing library Ghost.
- The inspiration came from last week's HEIF Heist: libheif (affected) is bundled into libvips, which ships with sharp, the popular Node.js image library. Patches exist, but users must update the dependency themselves.
- The repro is notably AI-flavored: he had MiniMax M3 build a working PoC image file and script, exploiting loose file-extension logic to bypass MIME type checks.
- The PoC reliably crashes the container, and he believes there may be room for code execution as well.
Related event: Researcher Lands First CVE with AI-Generated PoC for Ghost Flaw(3 posts)→
More from coding & agent
- Handy Claude Code mod renders Mermaid diagrams right in the terminal — teropa · 2026-10-02
- Desearch MCP Server Brings Real-Time AI Search on X and the Web to Agents — modelcontextprotocol · 2026-10-02
- Waysway Launches Travel MCP Connector for Hotels, Flights and Restaurants — modelcontextprotocol · 2026-10-02
- Dev lets Sol Ultra improve his engine for 2 hours — usage barely moved 2% — Dimillian · 2026-10-02
- Meme: Developers hitting 'Allow' in Claude Code over and over — aishashok14 · 2026-10-02
- Microsoft's Autopilot isn't Scout 2.0: a private-preview shift to a Foundry-hosted cloud agent platform — pswider · 2026-10-02