Larson: Are insecure code completions a vulnerability? (opens in new tab)
Seth Larson, the Python Software Foundation's , has the difficulty in classifying insecure code completion in the using its plugin. Larson discovered that the plugin, which uses a local "deep learning module" to offer code completions, suggests code that would lead to severe vulnerabilities. He was unsure whether it warranted a CVE or not, however: I reported this behavior to JetBrains for "Full Line Code Completion" v253.29346.142 and clearly their support staff weren't certain whether this ...
Read the original article