- Sources: primary, discussion
- Summary: The post names four conditions that must all hold: Sentry Seer in use, Seer set to hand issues to a coding agent automatically, automated remediation enabled so the agent acts without a human starting each run, and a project collecting frontend errors through a public DSN, and it states that the automatic path does not apply in the same way when a human triggers and reviews Seer before the agent acts. A frontend DSN is public by design and permits only sending events, so on such a project anyone can submit a crafted error report without an account, after which the agent acts on the fabricated report while holding a credential scoped to the connected repositories and before any pull request exists for a human to review. The disclosure, which the post calls PhantomFix and dates 2026-09-14, withholds the report contents, the trigger and the reproduction until a fix exists, names no affected version, and Sentry has published nothing. The ids CVE-2026-90999 and CERT/CC VU#212479 are the researcher's own citations and are not confirmed here against a vendor advisory.
- Why it matters: A frontend DSN is public by design and only permits sending events, so the attacker needs no account, and the agent acts on the fabricated report while holding a credential scoped to the connected repositories and before any pull request exists to review.
- Follow-up: Track a Sentry advisory, a fixed version, and publication of the withheld trigger and reproduction.
send feedback on this story