PT-2026-78153 · Undefined · Undefined
CVE-2026-73855
·
Publicado
2026-08-18
·
Atualizado
2026-08-18
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Full disclosure: I’m Atto’s solo developer.
A structured Hermes audit found a critical flaw in Atto’s live vote handling. I verified it, stopped the release, and fixed it last month in node v1.33. It is now CVE-2026-73855, rated CVSS 9.3.
Later, gpt-5.6-sol in Codex independently found the exact same flaw without my purpose-built audit workflow. It still missed several less severe findings that the structured audit caught.
The experience changed how I think about context, subagents, and AI security reviews:
Are native Codex subagents enough for large security reviews now, or do you still use an explicit task and evidence structure?
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined