Skip to content
Hacker News front page

PyCharm's full-line completion suggests disabling TLS verification—is that a vulnerability?

Are insecure code completions in PyCharm a vulnerability?

Seth Larson tested PyCharm's local full-line completion plugin and found it suggests cert_reqs='CERT_NONE' and disable_warnings right after importing urllib3—effectively writing a MITM vulnerability for the developer. JetBrains said the report wasn't a direct security vulnerability but also asked him not to publicize it under their coordinated disclosure policy. After 90 days with no substantive update, the latest plugin version still produces the same insecure suggestions. Larson argues CVEs aren't the right tool here, but leaving these defaults unaddressed shifts risk onto users who trust their IDE's suggestions.

Why it matters: The author personally reproduced PyCharm's full-line completion suggesting insecure code, reported it to JetBrains, and got stonewalled for 90 days. Complete story with concrete evidence. Hits all three HKR axes, but sits at the security-tooling intersection rather than indust...

Read the original ↗Export Markdown