Huntarr - Your passwords and your entire arr stack's API keys are exposed to anyone on your network, or worse, the internet

12 points by tiff


ksynwa

What does huntarr do? Seems like all traces of it have been wiped from github.

mdaniel

whew I'm on the fence about /t/vibecoding applied to this, since that's arguably what it's about, but the post itself only does the tiniest amount of vibecoding for the repro script

Anyway, in case someone wants a non-reddit flavor https://github.com/rfsbraz/huntarr-security-review/blob/main/Huntarr.io_SECURITY_REVIEW.md is the meat-and-potatoes without all the subreddit drama

dubiouslittlecreature

This is obviously a worst case scenario but there's a reason I don't trust slopware.

rplacy

where did the huntarr go from github? I get 404