frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Vulnerabilities in 45 Open Source Projects (vLLM, Langfuse, Phase, NocoDB)

https://www.kolega.dev/blog/why-we-found-225-security-flaws-in-45-open-source-projects-that-sast-missed/
2•jfaganel99•1h ago

Comments

jfaganel99•1h ago
Author here. We built a security scanner called Kolega that does semantic analysis instead of pattern matching. To see if it actually worked, we ran it against 45 open source projects and reported what it found through responsible disclosure.

225 vulnerabilities. 41 reviewed by maintainers so far, 37 accepted, 4 rejected. 90% acceptance rate.

The bugs weren't exotic. They were things like:

if not user_id is not None - a double negative in Phase that means the permission check never runs. Nine auth bypasses total.

torch.load() without weights_only=True in vLLM - RCE via pickle deserialization in one of the most popular inference frameworks.

RestrictedPython sandbox in Agenta where __import__ was explicitly added to safe_builtins. Four different escape routes to arbitrary code execution.

SQL injection in NocoDB's Oracle client - Semgrep scanned the same codebase and found 222 issues, 208 of which were false positives, and missed this one entirely.

The interesting part to me wasn't that we found bugs. It's that these are all syntactically correct - the code compiles, runs, looks fine in review. The problems are semantic. No pattern matcher catches not X is not None because it's valid Python. You have to understand what the developer intended.

Every finding is published with full details - code locations, CWEs, PR numbers, disclosure timelines: https://www.kolega.dev/security-wins/

135 findings are still waiting on maintainer response. 4 were rejected - some we thought were exploitable, maintainers disagreed. We document those too.

Happy to discuss specifics on any of the projects or argue about methodology.

Daemon (Novel)

https://en.wikipedia.org/wiki/Daemon_(novel)[2006]
1•nailer•1m ago•0 comments

Programming Aphorisms

https://matklad.github.io/2026/02/11/programming-aphorisms.html
1•ibobev•6m ago•0 comments

Railway Global Outage

https://status.railway.com
1•TealMyEal•6m ago•0 comments

Show HN: Turn Strava activities into GitHub-style contribution heatmaps

https://github.com/aspain/git-sweaty
1•aspaindev•7m ago•0 comments

Third day of the week with a GitHub incident

https://www.githubstatus.com/incidents/frlwqbqgz113
1•gionn•7m ago•0 comments

Why Vampires Live Forever

https://machielreyneke.com/blog/vampires-longevity/
1•machielrey•8m ago•0 comments

Prompt Mixer - real-time LLM steering UI

https://github.com/Jitera-Labs/prompt_mixer.exe
1•everlier•9m ago•1 comments

Recreating Hi8

https://alexkranias.com/essays/hi8.html
1•alexkranias•10m ago•0 comments

Text classification with Python 3.14's ZSTD module • Max Halford

https://maxhalford.github.io/blog/text-classification-zstd/
1•rbanffy•10m ago•0 comments

Show HN: Host OpenClaw with native template and multi-agent support

https://clawclaw.click/
1•Jacques2Marais•10m ago•0 comments

Lessons learned building a Node.js malware scanner to 400 stars (Open Source)

1•alrjoe•11m ago•0 comments

Attention Sinks and Compression Valleys in LLMs

https://arxiv.org/abs/2510.06477
1•alexkranias•12m ago•0 comments

Part 2 - AI Chat Evaluation of the Formal Language in He Xin's PEPC System

1•nikicsy•12m ago•0 comments

Hand tool rewrites ancient Egyptian history

https://www.popsci.com/science/ancient-egypt-hand-tool/
1•delichon•12m ago•0 comments

A note about personal security

https://werd.io/a-note-abo/
1•sdoering•13m ago•0 comments

Part 1 - AI Chat Evaluation of the Formal Language in He Xin's PEPC System

1•nikicsy•13m ago•0 comments

A Note on File History in Emacs

https://brainbaking.com/post/2026/02/a-note-on-file-history-in-emacs/
1•Brajeshwar•14m ago•0 comments

Revisionist History – Aliens, Secrets and Conspiracies

https://steveblank.com/2026/02/10/revisionist-history-aliens-secrets-and-conspiracies/
1•Brajeshwar•14m ago•0 comments

Show HN: cbt (C++ Build Tool)

https://github.com/swar-mukh/cbt
1•swar-mukh•14m ago•0 comments

Open model StepFun-3.5 is #1 on MathArena, an uncheatable math benchmark

https://twitter.com/CyouSakura/status/2021511358626554322
1•diyer22•14m ago•0 comments

Show HN: Bitcoin, GEB, and Bach's fugues share the same structural move

https://falsework.dev/
1•falsework•14m ago•1 comments

Functional Programming in M4

https://minnie.tuhs.org/pipermail/tuhs/2020-August/022108.html
1•fanf2•16m ago•0 comments

AI makes it easier to build the wrong thing faster

https://newsletter.masilotti.com/p/ai-makes-it-easier-to-build-the-wrong
1•joemasilotti•16m ago•1 comments

Show HN: I built a macOS desktop toy that patrols while you work

https://airwolfspace.com/tinytanks
1•kailuo•16m ago•0 comments

Poison at Play: Unsafe lead levels found in half of New Orleans playgrounds

https://veritenews.org/2026/02/05/poison-at-play-playgrounds-lead-levels/
1•hn_acker•16m ago•0 comments

Unresponsive Buttons on My Fastest Hardware

https://blog.jim-nielsen.com/2026/unresponsive-buttons/
2•speckx•16m ago•0 comments

AI-First Company Memos

https://the-ai-native.company/
16•bobismyuncle•16m ago•0 comments

How to Test ProxySQL Read/Write Split with Sysbench

https://rendiment.io/mysql/proxysql/2026/02/03/sysbench-proxysql.html
1•nethalo•18m ago•0 comments

The singularity won't be gentle – by Nate Silver

https://www.natesilver.net/p/the-singularity-wont-be-gentle
4•rbanffy•19m ago•1 comments

A New Computer Could Replace Electricity with Light

https://www.popularmechanics.com/science/a70223544/computer-could-replace-electricity-with-light/
1•falcor84•19m ago•0 comments