[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-security-firm-beats-ai-models-to-six-curl-bugs":10,"sections":46},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":35,"tags":36,"sources":41,"feedback":45,"feedback_at":22,"cost_usd":45,"total_tokens":45},5999,"security-firm-beats-ai-models-to-six-curl-bugs","Security Firm Beats AI Models to Six curl Bugs","Aisle says it found six curl vulnerabilities that OpenAI and Anthropic tools reportedly missed, though the source omits CVE numbers and severity.","A security firm just did what OpenAI's and Anthropic's tools reportedly could not: find six bugs in curl.\n\nAisle, a security research outfit, says it audited curl, the widely used command-line tool and data-transfer library, and turned up six vulnerabilities. According to Aisle's account, OpenAI and Anthropic had already reviewed the same codebase with their own tools and reported finding zero issues. The claim first appeared as a blog post, then reached Hacker News, where it collected 60 points and 22 comments. The available summary does not include CVE identifiers, severity ratings, or the curl version tested, details that would let outside engineers actually verify the claim.\n\ncurl runs inside nearly every operating system, router, and internet-connected app, so a six-bug gap is not trivial if it holds up. The more interesting story is what it implies about AI-assisted code review: two well-funded labs' tools reportedly missed everything that a smaller, human-led audit caught.\n\nUntil Aisle or the curl project publishes the technical writeup (patch notes, CVE numbers, proof-of-concept code), treat \"zero\" as an unverified claim about AI tooling and \"six\" as an unverified claim about curl. Neither number means much without the paperwork.","[\"curl\",\"vulnerability-research\",\"ai-security\",\"open-source\"]","2026-09-02T13:43:14.000Z","2026-09-02T15:55:17.930Z","2026-09-02T15:55:29.853Z","published",null,[24,30],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The only source material given is a bare Hacker News listing (title, URL, points\u002Fcomments) with no actual blog content, so the draft states specifics — that all six issues are 'confirmed' CVEs, and the detail that OpenAI's and Anthropic's tools scanned the identical codebase and returned nothing — as settled fact when these are Aisle's own unverified, self-reported claims from a promotional blog post; pull actual CVE identifiers, curl version, and severity from the Aisle post and attribute the A","resolved",{"id":31,"reviewer":32,"round":33,"reason":34,"status":29},"publisher-r2","publisher",2,"The body omits curl's version number, CVE identifiers, and severity ratings for the six claimed bugs, so key facts are unverifiable rather than just appropriately skeptical.","security",[37,38,39,40],"curl","vulnerability-research","ai-security","open-source",[42],{"name":43,"url":44},"Hacker News","https:\u002F\u002Faisle.com\u002Fblog\u002Faisle-discovered-six-curl-cves-after-openai-and-anthropic-found-zero",0,{"sections":47},[48,53,57,62,67,72,77,82,87,92,97,102,107,112],{"name":49,"slug":50,"count":51,"latest_published_at":52},"AI","ai",3385,"2026-09-04T22:17:36.000Z",{"name":54,"slug":35,"count":55,"latest_published_at":56},"Security",565,"2026-09-05T00:03:08.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Policy","policy",300,"2026-09-04T22:18:34.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Hardware","hardware",152,"2026-09-03T09:26:48.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Consumer Tech","consumer-tech",97,"2026-09-04T15:29:18.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Science","science",96,"2026-09-03T22:30:00.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Startups","startups",54,"2026-09-04T23:36:14.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"General","general",37,"2026-09-04T20:22:41.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":113,"slug":114,"count":115,"latest_published_at":116},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]