Property-Based Testing Caught a Security Bug I Never Would Have Found

kiro.dev

19 points by nslog 9 hours ago


mananaysiempre - an hour ago

TL;DR: obj[key] with user-controlled key == "__proto__" is a gift that keeps on giving; buy our AI tool that will write subtle vulnerabilities like that which you yourself won’t catch in review but then it will also write some property-based tests that maybe will