Is this #curl security report AI slop or not? hackerone.com/reports/3303765

  • slop (73%, 328 votes)
  • not slop (26%, 119 votes)
447 voters. Poll end: 1 week ago

#curl
in reply to daniel:// stenberg://

Not necessarily genAI. but definitively slop.

Could be there was actually a bug/glitch in the Kali WSL/potential Microsoft "curl"/hacking some webserver stack.
I would not consider this environment reliable in any possible sense.
It can be expected to at least spin up a clean VM and test your claims against a more simple/basic stack. Clearly that was not done.

in reply to daniel:// stenberg://

I originally voted for 'not slop', but then no Debian/Ubuntu/Kali release has curl 8.13.0, so I am not sure anymore. It is probably AI-assisted thing.

curl 8.15.0-3 was in Kali rolling between 2025-05-08 and 2025-06-12;

I've tried building 8.13.0-5 package in Debian Trixie to match that one of the reporter and the memory is stable. So ... probably AI was involved.