Security researcher uses MiniMax M3 to build PoC for CVSS 8.8 bug in sharp's dependency chain
xeophon · x · 2026-10-04
Security researcher @xeophon reports his first CVE: a CVSS 8.8 memory corruption bug in Ghost. The trail started with last week's HEIF Heist vulnerability in libheif, which is bundled into libvips, which in turn is bundled into sharp, a widely used Node.js image processing library. Patches exist, but users must update their dependencies to be protected.
To reproduce the issue, he had MiniMax M3 build a working PoC image file and script, demonstrating a concrete LLM-assisted security research workflow — and a reminder for Node ecosystem users to update the sharp dependency chain.
More from Safety
- White House forms AI task force with 120 days to assess risks and federal responsibility — ShakeelHashim · 2026-10-04
- Yacine: recommendation hit him with no cookies, just age and gender — yacineMTB · 2026-10-04
- Bot Gaffe Catalogs Hundreds of AI Failures, from a $7,100-Denying Agent to Rogue OpenAI Breaches — SuB8u · 2026-10-04
- Report: China's growing DUVi stockpile could erase US AI chip edge within a decade; ban urged — teortaxesTex · 2026-10-04
- Vitalik's privacy-preserving personal AI: local Qwen orchestrator + zkAPI + Tor, no data leaks — kenziyuliu · 2026-10-04
- Dev builds Browser MCP Defense demo with ampcode, seeks design partners — HankYeomans · 2026-10-04