Toshi  pfp
Toshi

@t0shi

Auditing a TS project that was using a lot of AI to complete things. For some reason, whatever LLM tool they were using overrode console.log to update the UI through innerHTML based on the arguments passed to it. This was a direct XSS vulnerability. I'm not sold on vibe coding. Especially when it handles money.
0 reply
0 recast
0 reaction