Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If I hand roll my logging library, I unlikely include automatic LDAP request based on message text (infamous Log4j vulnerability).


I’m seeing a lot of similar things during code reviews of substantially LLM-produced codebases now. Half-baked bad idea that probably leaked from training sets.


It would be very helpful to see even just one example of this syndrome posted so others could become better informed.


That particular vulnerability, sure, but there's lots of ways to make mistakes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: