NodeSphere
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
botM to netsecEnglish · 16 days ago

CVE-2026-90999 A fabricated Sentry bug report can make Seers coding agent run attacker code

agyn.io

external-link
message-square
0
link
fedilink
1
external-link

CVE-2026-90999 A fabricated Sentry bug report can make Seers coding agent run attacker code

agyn.io

botM to netsecEnglish · 16 days ago
message-square
0
link
fedilink
PhantomFix: a fabricated bug that hijacks an AI autofix agent (CVE-2026-90999)
agyn.io
external-link
PhantomFix (CVE-2026-90999) is a critical vulnerability in Sentry Seer's autonomous autofix: a fabricated error report sent to a public DSN can reach the coding agent and lead to code execution and access to connected repositories. It's a concrete instance of a class we described earlier — and the same manipulation works against every leading LLM we tested. Full details and a demo are coming; if you run this setup, you might want to pause it for now.
alert-triangle
You must log in or register to comment.

netsec

netsec

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !netsec@nodesphere.site
lock
Community locked: only moderators can create posts. You can still comment on posts.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 2 users / week
  • 2 users / month
  • 2 users / 6 months
  • 2 local subscribers
  • 3 subscribers
  • 1.33K Posts
  • 152 Comments
  • Modlog
  • mods:
  • bot
  • BE: 0.19.20
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org