Skip to main content


We disclosed this #hackerone report against #curl when someone asked Bard to find a vulnerability, and it hallucinated together something:

hackerone.com/reports/2199174

in reply to daniel:// stenberg://

{"error": "too many requests"}

You've hacked hackerone (remote DoS, 9.8 CVSS)

This entry was edited (1 year ago)
in reply to daniel:// stenberg://

And the report is that the fixes for the vulnerability are posted on the Internet? This is so ridiculous.
in reply to daniel:// stenberg://

“I have searched in the Bard about this vulnerability”. Right there is the problem. LLMs are not search engines. This is similar to the attorney that “searched” for case law using ChatGPT and ended up filing a legal argument full of references to made up cases.
in reply to daniel:// stenberg://

it’s all the weirder because they aren’t even trying to report a new vulnerability. Their complaint seems to be that detailed information about a “vulnerability” is public. But that’s how public disclosure works? And open source? Like are they going to start submitting blog posts of vulnerability analysis and ask curl maintainers to somehow get the posts taken down???
in reply to daniel:// stenberg://

oh as in saying the embargo was broken but with LLM hallucinations as the evidence?
in reply to daniel:// stenberg://

Bard doing bard things - writing entertaining stories that are nothing more than myth. All it needs is a lute and a penchant for rough taverns.
in reply to daniel:// stenberg://

I suspect the reporter's last comment in that thread was also written by an LLM
in reply to daniel:// stenberg://

On the plus side, they pretty much started with "I asked the Bard". Imagine if that bit had not been there?
in reply to daniel:// stenberg://

That LLM crap keeps giving and giving. Can't we just uninvent it please?
Unknown parent

daniel:// stenberg://
@kurtseifried right, it is fortunate as long as the bad ones are this easy to detect and dismiss, It is going to get worse when we get overloaded with submissions that are less easy to discard early...
in reply to daniel:// stenberg://

This is wonderfully bizarre. As I understand it, Bard has had a hallucination and dreamt up a leak before public disclosure - including the details of not-yet-released material.
Makes me wonder: how off are these hallucinations? Are they anywhere closely resembling the truth? Or partial? Or in the correct region?
in reply to Dan Bergh Johnsson

@danbjson This seems to be using the bogus CVE 2020-19909 as a base and then synthesizing fake functions around it
in reply to Brodie Robertson

exactly. It seems "inspired" mostly by 19909, and then adds a mishmash of weirdo inconsistent details. The mention of 38545 and 8.4.0 indicate it actually knows at least they exist. Possibly because they were used in the prompt?
This entry was edited (1 year ago)
in reply to daniel:// stenberg://

@BrodieOnLinux Bard is continuously connected to internet, isn’t it? So it could snap up the news about 8.4.0 from other news sources, couldn’t it? Though “from the prompt” sounds more plausible.
in reply to daniel:// stenberg://

I love your restraint.
My reply would have certainly contained the phrase "fucking idiot".