AI agents found cohttp path-traversal exploit within minutes of PR being opened
OCaml maintainer Anil Madhavapeddy disclosed a path traversal vulnerability in cohttp 6.3.0 and found that attackers began probing his live server with the exact exploit pattern just minutes after he opened a public GitHub pull request to fix it. He also demonstrated that AI coding agents like DeepSeek V4 Pro could independently rediscover the bug and build a working exploit in under a minute, using only a vague description of the issue.