Explore Problems
Showing 245 of 9,941 problems · matching your filters
AI-generated vibe-coded apps ship with live security holes
Applications built quickly with AI coding tools like Replit, Lovable, and Cursor often go to production with unaddressed access-control vulnerabilities, and their builders typically lack security expertise. High engagement (532 upvotes) suggests broad resonance, though it surfaces via a solution launch rather than direct user complaints.
AI Agent Loops Are Opaque: Silent Failures Hidden Behind 200 OK Responses
AI agents running in production can silently loop, replay the same tool call for minutes, or stall — while HTTP logs show clean 200 OK responses. Standard observability tools have no concept of multi-turn agent behavior, leaving engineers blind to the actual agent execution path. Diagnosing these failures requires deep network-level inspection of LLM traffic that no mainstream APM tool provides.
Safety-Critical Professionals Cannot Search Large Technical Manuals Under Time Pressure
Pilots, engineers, and technicians must locate precise data buried in 600-page PDFs during time-sensitive workflows, but manual searching is slow and cloud AI tools require uploading sensitive or classified documents. The need for fast, accurate, offline document querying is unmet by current tools.
Mortgage servicers initiate foreclosure while loss mitigation review is active
Homeowners who submit loss mitigation applications to pause foreclosure proceedings find servicers simultaneously advancing the foreclosure, violating RESPA dual-tracking prohibitions. The process moves faster than any complaint or escalation path, leaving borrowers facing property seizure without legal recourse in time.
AI Assistants Reset to Zero Context Each Session
Every new AI session starts without memory of prior conversations, project context, or established preferences. Users spend significant time re-establishing context that should persist, and knowledge built up over time disappears when the tab closes. Approaches that compound knowledge across sessions rather than re-deriving it each time represent a fundamental gap in current AI assistant design.
AI Code Reviewers Miss Race Conditions and Critical Concurrency Bugs
AI-powered code review tools fail to detect race conditions and TOCTOU vulnerabilities due to context blindness, leaving critical billing and security bugs undetected in production.
Legacy System Business Logic Is Inaccessible to Non-Technical Stakeholders
Critical business logic embedded in legacy code is only accessible through engineering mediation, creating bottlenecks and knowledge silos as the original developers leave or retire. Business stakeholders and architects cannot independently understand their own systems. AI-assisted code explanation that surfaces business logic for non-technical users could eliminate this structural dependency.
Multi-Tenant SaaS Apps Risk Cross-Customer Data Leaks
Developers building multi-tenant SaaS platforms from scratch can inadvertently create data isolation bugs that let one customer see another customer's data, a serious security failure often discovered only after a user reports it. This risk drives some builders to seek pre-built, vetted multi-tenancy infrastructure instead of implementing it themselves.
Navigating Health Insurance Claim Denials for Necessary Treatment
Patients whose insurers deny coverage for treatments they believe are medically necessary face a confusing appeals process, needing to parse dense policy language and Evidence of Coverage documents to determine if a denial was valid. The frustration is compounded by tight response deadlines and the burden falling on patients already dealing with illness.
GitHub Security Breaches and Outages Drive Developers Away From Private Repository Hosting
Multiple GitHub security incidents including private repository leaks and git push exploits are eroding developer trust in hosted private repositories. Service outages compound the reliability concern for teams depending on GitHub for CI/CD pipelines and code collaboration. Self-hosted alternatives like Gitea require setup expertise that most teams lack.
Freelance devs hit with malware repos disguised as client briefs on Upwork/Dribbble
Fake clients on freelance platforms send GitHub repos that exfiltrate browser credentials, SSH keys, and crypto wallets when developers run npm install. The Contagious Interview / GitVenom pattern is widespread enough that 390 upvotes engaged in a single share; current tooling does not surface threat before clone-and-run.
AI-Generated Content Contains Hallucinations and Weak Citations With No Automated Verification
AI language models produce content with hallucinated facts, fake citations, and flawed logic at a speed that outpaces manual human review. Teams using AI for content creation have no scalable way to verify accuracy before publication without a secondary review system. The absence of automated AI output verification creates compounding credibility risk as content production accelerates.
Cloud Cost Spikes Lack Automated Root Cause Explanation
When cloud bills spike unexpectedly, DevOps engineers and FinOps practitioners must manually drill through Cost Explorer filters without receiving a clear explanation of which services drove the change or why. Native cloud billing tools surface the 'what' (a cost increase) but not the 'why' (which service, usage type, or behavioral shift caused it), forcing teams into time-consuming manual investigation. This gap becomes acute under executive pressure, when speed of diagnosis directly affects business decisions around budget and resource allocation.
Established small businesses cannot access emergency credit when one bad year disqualifies them from traditional lending
Businesses with 10+ year track records are denied lines of credit after a single loss year due to rigid bank underwriting, leaving viable companies with days of runway and no recourse. The gap between emergency need and bank approval timelines can kill otherwise healthy businesses.
Shopify Merchants Report Unfair Chargeback Dispute Resolution and Deceptive Shop App Ads
A Shopify merchant describes the Shop App advertising program as misleading, draining ad budgets without transparency, and says Shopify's chargeback dispute process consistently favors buyers over sellers while charging high dispute fees. The complaint points to a structural imbalance in how the platform handles advertising accountability and payment disputes for merchants.
Cloud Documents Permanently Deleted With No Recovery After a Hard Trash Window
A user's entire set of Google Docs and Sheets files vanished, leaving only empty folders, and support said recovery was impossible because the files had passed a roughly 25-day trash retention window. Relying solely on the cloud provider's built-in trash leaves users with no independent backup or version history once that window closes, turning a routine deletion into permanent, unrecoverable data loss.
Prepaid Card Issuers Missing Statutory EFT Dispute Deadlines and Backdating Records
A prepaid card holder disputing unauthorized activity found the issuer missed the federally mandated investigation deadline, then allegedly backdated internal ledger records to appear compliant. This points to a gap in independent, tamper-evident documentation tools that let consumers prove dispute timelines when card issuers control all the records.
Sales Reps Lose Deals Because Manual Follow-Up Tracking Fails at Scale
Salespeople and founders consistently drop deals not from poor sales skills but from forgetting to follow up at the right moment. Manual reminders in calendars or CRMs require discipline to maintain and degrade as pipeline volume grows. Automated, context-aware follow-up nudges represent a high-value, high-willingness-to-pay solution.
Vehicles get repossessed without proof the required default notice was ever sent
Lenders repossess vehicles while unable to produce mailing dates, notice copies, or any proof that the legally required Notice of Default was sent beforehand, and the only documentation is a Notice of Sale issued after the fact. Because verification of proper notice happens only after repossession, borrowers have no way to confirm compliance in advance and can lose critical transportation for medical or income needs with no warning.
Prepaid card issuers withhold Reg E provisional credit during fraud review
After reporting unauthorized ATM withdrawals and filing a formal fraud claim, a cardholder followed up multiple times but received only generic status updates, with no provisional credit issued as required under Regulation E while the investigation is pending. This leaves fraud victims financially exposed during the review period despite following the required reporting process.