this post was submitted on 02 Jan 2024
4 points (100.0% liked)

Programmer Humor

35334 readers
1 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 6 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[โ€“] MyFeetOwnMySoul@lemmy.ca 0 points 2 years ago (1 children)

How does this exploit work? I understand that inputs were not sanitized, but what did the injected code do?

[โ€“] powerofm@lemmy.ca 1 points 2 years ago

My guess would be the response text is passed through a rudimentary templating engine that looks for { and }. Somehow it must be processing the whole chat history. The templater fails at the unexpected braces in the code block and then just gives up (probably a try-catch ignores the error and sends the message anyway).