Open source project curl is sick of users submitting “AI slop” vulnerabilities
Published on: 2025-07-26 06:49:24
Ars has reached out to HackerOne for comment and will update this post if we get a response.
“More tools to strike down this behavior”
In an interview with Ars, Stenberg said he was glad his post—which generated 200 comments and nearly 400 reposts as of Wednesday morning—was getting around. "I'm super happy that the issue [is getting] attention so that possibly we can do something about it [and] educate the audience that this is the state of things," Stenberg said. "LLMs cannot find security problems, at least not like they are being used here."
This week has seen four such misguided, obviously AI-generated vulnerability reports seemingly seeking either reputation or bug bounty funds, Stenberg said. "One way you can tell is it's always such a nice report. Friendly phrased, perfect English, polite, with nice bullet-points … an ordinary human never does it like that in their first writing," he said.
Some AI reports are easier to spot than others. One accidentally pasted their prompt
... Read full article.