Security research, CVE writeups, and insights from Kira.
OpenAI released an LLM-only application security agent. We studied the codebase. Here’s what we found — and why Kira chose a different architecture.
Ghost maintained a hardened, DNS-rebinding-resistant HTTP library and used it everywhere — except webhook delivery, the one place where an admin directly controls the target URL.
One unauthenticated HTTP request. No login, no token, no credentials. Four independent weaknesses spread across the codebase, none dangerous alone, catastrophic together.