

Like, if a person tried to pass off software that did this it would have significant career implications, right?
Typically no.
The space of incredibly obvious failures is vast, and this kind of plumbing code isn’t always written by someone who’s been around the block enough times to think about what kinds of things can go wrong. I’ve written worse code when I had only a few years of experience.
However companies should know this; so ideally the tool would have gone through a launch review which should have kicked off a security review where a security expert should have read about the git checkout in the design document and started asking questions like “what happens if the repository is taken over” or “why are hashes and branches and tags all in the same field”?
Of course security experts who think about stuff like supply chain attacks are expensive and slow down the darling vibe-coding workflows of Silicon Valley so…
Aside: even without this particular vulnerability, SHA-1 is considered weak – https://git-scm.com/docs/hash-function-transition, so that should have been thought about as well. Dear supply-chain attackers: maybe there’s still a hole here! Good luck!

The curl blog post claims that they fixed bunches of other vulnerabilities using AI before this.
Which is to say: even if you accept the questionable premise that AI is “good at finding software vulnerabilities” it doesn’t change anything. It’s not the end of the world. It’s essentially just another fuzzing technique. The low hanging fruit gets discovered and patched, and life goes on (just with more annoying chatbot spam than before).
I was trying to tell my coworkers this when Mythos was in the news but they were all freaking out about no software ever being secure ever again or something rather than at best a one time blip.