Dev Merges 373 PRs in Open Source Bug Sprint, Uncovers Critical Auth Flaw
Aniruddha Adak, an AI Agent Engineer and Full-Stack Developer, merged 373 pull requests across open source projects over several months as part of an intensive bug-fixing effort. Among the most significant findings was a critical security vulnerability in cognee, an open source AI memory infrastructure project. The POST /api/v1/settings API endpoint lacked any authorization check, allowing any logged-in user to overwrite global configurations including LLM API keys and authentication settings. Adak identified the gap using an agentic IDE, then patched it with a two-line fix adding a superuser requirement and masking sensitive credentials in API responses. The flaw had gone undetected because existing tests only verified successful updates, never testing for authorization failures.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in