Canva AI Critical Vulnerability
Okay, learned friends, what do you recommend? I discovered a critical security vulnerability using @Canva AI. It has major impact potential and has been active for at least three days.
I emailed them. They said "report it using Bug Bounty." Of course, I'd already done that. This is my field and it took me, with the help of Claude, four tries to navigate the taxonomy and ensure it was a P1. (It is definitely that.)
A lay person would have had no clue how.
Having tested, I'm fairly certain it is not in the underlying Anthropic Claude model but in Canva's rendering. But obviously, it impacts trust in that tool as well.
I would not share details of a vulnerability; I'd get it fixed. That's failed ... would you share the details of the vulnerability? Warn people off the platform?