Was bad prompting responsible for the HuggingFace incident?
It turns out the ExploitGym prompt is remarkably bad at explaining intent to agents. I benchmarked how agents respond to broken tasks w/ different prompts and the ExploitGym one was the only prompt that led to cheating!
Our team discovered a critical remote code execution vulnerability in Next.js.
If you self-host Next.js, update immediately. Vercel managed Next.js hosts are safe!
We’ll publish the technical details and proof of concept soon!