Security posture overview
Canonical security findings across your organization
| ID | Title | Repository | Severity | CVSS | EPSS | Source | Status | R |
|---|---|---|---|---|---|---|---|---|
| KG-0E4E07 | ZIP Slip Path Traversal: Arbitrary File Write to Server File... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-090F8A | Sensitive Data in JWT Payload: MD5 Password Hash Exp... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-114331 | IDOR Write Access: Modify or Delete Any User’s Basket I... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-074374 | XML External Entity (XXE) Injection: Arbitrary File Read vi... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-855CAA | Sensitive Data Exposure: Password Hashes and DeluxeTo... | test/juice-shop | Critical | – | – | Blackbox Pentest | Open | – |
| KG-EC0DBE | Sensitive Information Disclosure: Admin Configuration E... | test/juice-shop | Medium | – | – | Blackbox Pentest | Open | – |
| KG-94ADCF | ZIP Path Traversal: Arbitrary File Write to Publicly Served... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-E2C6A5 | IDOR Write/Delete: Unauthorized Modification and Deleti... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-49777C | IDOR: Unauthorized Read Access to Any User’s Shoppin... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-417855 | Broken Access Control: Admin User Data Exposed to Cus... | test/juice-shop | High | – | – | Blackbox Pentest | Open | – |
| KG-9B50D6 | Unauthenticated FTP Directory Exposure: Sensitive Files,... | test/juice-shop | Critical | – | – | Blackbox Pentest | Open | – |
| KG-7823AD | Account Takeover via Publicly Exposed Security Question ... | test/juice-shop | Critical | – | – | Blackbox Pentest | Open | – |
| KG-0F233C | Horizontal Authorization Bypass: Email Vowel-Obfuscati... | test/juice-shop | Medium | – | – | Whitebox Pentest | Open | – |
| KG-9301D0 | Horizontal Authorization Bypass: Email Vowel-Obfuscati... | test/juice-shop | Medium | – | – | Whitebox Pentest | Open | – |
The CI pipeline fetches an installer script from a self-hosted Heroku CDN endpoint and immediately pipes it to sh for execution without any integrity verification.
POST /file-upload (accessed via /#/complain complaint form)UNSPECIFIEDTOKEN=$(python3 -c " import urllib.request, json data = json.dumps({'email': 'recon-fresh@blackbox-dast.local', 'password': 'Recon@Test2024!'})...")'../..' to escape the upload directory. python3 -c " import zipfile, io buf = io.BytesIO() with zipfile.ZipFile(buf, 'w') as zf: zf.writestr('../../ftp/zipslip_confirmed.md', '# ZIP Slip Confirmed\nThis file was written via ZIP Slip path traversal.\nPayload: ../../ftp/zipslip_confirmed.md\n...')curl -s -w "HTTP: %{http_code}\n" \ -X POST 'https://shop.staging.example.com/file-upload' \ -H "Authorization: Bearer $TOKEN" \ -F "file=@/tmp/evil_zipslip.zip;type=application/zip" # Expected: HTTP 204/ftp/ by accessing it directly. curl -s 'https://shop.staging.example.com/ftp/zipslip_confirmed.md' # Expected: HTTP 200 with attacker-controlled contentBB-15: ZIP Slip Path Traversal: Arbitrary File Write to Server Filesystem via /file-upload (High)
OWASP: A01:2025 – Broken Access Control Endpoint: POST /file-upload (accessed via /#/complain complaint form) Auth State: Authenticated customer (recon-fresh@blackbox-dast.local)
The file upload endpoint processes ZIP archives without sanitizing entry paths for directory traversal sequences. An authenticated customer can create a ZIP file containing an entry with a filename such as ../../ftp/attacker.md, which the server extracts to a path outside the intended upload directory. Files written to /ftp/ are immediately publicly accessible via the web. Existing files, including application files, can be overwritten. The upload directory is exactly two levels below /ftp/, making traversal trivial. Escalation to Remote Code Execution is plausible if the traversal depth is sufficient to overwrite Node.js module files or application routes.
Generates an AI-authored fix and opens it as a pull request on the target repo. You review the diff and merge it; this finding auto-resolves once the PR lands.
Auto-patch isn’t available for GitLab repositories yet.
Autonomous penetration testing across your organization
| Target | Status | Exploits | Repositories | Created | Actions |
|---|---|---|---|---|---|
https://staging.example.com Black BoxStagingExploit | RunningTesting | – | juice-shop | 33 minutes ago | ⋯ |
https://staging.example.com White BoxStagingExploit | Running | 0 exploits | juice-shop | about 2 hours ago | ⋯ |
https://staging.example.com Black BoxStagingExploit | Failed | – | – | about 1 hour ago | ⋯ |
https://shop.staging.example.com Black BoxStagingExploit | Completed | View Report | juice-shop | 6 days ago | ⋯ |
https://staging.example.com Black BoxStagingExploit | Completed | View Report | – | 6 days ago | ⋯ |
https://demo.example.com White BoxStagingExploit | Canceled | 0 exploits | juice-shop | 6 days ago | ⋯ |
View detailed results from the autonomous penetration test
$username into the email or username field$password into the password field/
/apiFocus on REST API endpoints/restFocus on user-facing routes/#/score-boardSkip the score board meta-challenge pageThis security assessment of api.staging.example.com was conducted on April 23, 2026, targeting the application's REST API surface (/rest/*) with a focus on authentication, authorization, and data handling. The assessment uncovered 66 confirmed vulnerabilities (20 critical, 25 high, 20 medium, and 1 low) reflecting systemic compromised auth posture, unauthenticated attacker control over user identifiers via SQLi, broken JWT signature verification, and high-impact authorization bypasses across multiple commerce flows. Exploits worked end-to-end in a controlled environment (autonomous orchestrator + LLM-powered analysis) and a complete remediation roadmap is included alongside reproducible PoCs.
| ID | Vulnerability | Endpoint | Severity |
|---|---|---|---|
| INJ-VULN-01 | SQL Injection Authentication Bypass | POST /rest/user/login | CRITICAL |
| INJ-VULN-02 | SQL Injection UNION-Based Data Extraction | GET /rest/products/search | CRITICAL |
| AUTH-VULN-07 | JWT Algorithm None (alg:none) Authentication Bypass | ALL isAuthorized()-protected endpoints | CRITICAL |
| AUTH-VULN-10 | Default Admin Credentials | POST /rest/user/login | CRITICAL |
| AUTH-VULN-14 | Mass Assignment Privilege Escalation (Admin Role Registration) | POST /api/Users | CRITICAL |
| AUTH-VULN-18 | SQL Injection Authentication Bypass | POST /rest/user/login | CRITICAL |
| XSS-VULN-04 | Reflected XSS via Track-Order Parameter | GET /#/track-result | HIGH |
| XSS-VULN-06 | JSONP Callback Injection · Cross-Domain Data Theft | GET /rest/user/whoami | HIGH |
{
"id": "INJ-VULN-01",
"endpoint": "POST /rest/user/login",
"payload": "' OR '1'='1'--",
"response_code": 200,
"response_signature": "demo@example.com (id=1, role=admin)",
"reproduced": true
}
Detailed vulnerability analysis and reproduction information
Send POST /rest/user/login with tautology payload in email field
The injected SQL becomes: SELECT * FROM Users WHERE email = '' OR '1'='1'--' AND password = '...'
The -- comments out the password check; SQLite returns the first row (admin, id=1)
Observe HTTP 200 response containing admin JWT token
HTTP 200 returned with admin JWT token (email: demo@example.com, role: admin, id: 1). MD5 hash 0192023a7bbd73250516f069df18b500 = admin123 confirmed via rainbow table.
View detailed results from the autonomous penetration test
Every action recorded with actor, timestamp, and source
| Time | Event Type | Subject | Actor |
|---|---|---|---|
| Apr 27, 2026 08:02:38 | appsec:SubmitBoundarySelection | juice-shop | demo@example.com |
| Apr 27, 2026 07:50:57 | appsec:TriggerBoundaryAnalysis | juice-shop | demo@example.com |
| Apr 27, 2026 07:50:29 | appsec:TriggerManualScan | juice-shop | demo@example.com |
| Apr 27, 2026 07:21:01 | appsec:TriggerManualScan | vuln-bank | demo@example.com |
| Apr 27, 2026 06:39:51 | appsec:TriggerManualScan | juice-shop | demo@example.com |
| Apr 27, 2026 05:54:14 | appsec:TriggerManualScan | dvwa | demo@example.com |
| Apr 27, 2026 05:53:42 | appsec:TriggerManualScan | juice-shop | demo@example.com |
Manage users and invitations for your organization
| Name | Status | Role | Account Type | Link Status | Actions | |
|---|---|---|---|---|---|---|
| Alex Rivera | demo@example.com | Active | Member | User | Primary | ⋯ |
| Repository | Default Branch | Group | Last Scanned | ||
|---|---|---|---|---|---|
| local-dev-kg/juice-shop | master | Unassigned | about 8 hours ago | ⋯ | |
| test/juice-shop-appsec | master | Unassigned | about 8 hours ago | ⋯ | |
| local-dev-kg/AWSGoat | master | Unassigned | about 1 month ago | ⋯ | |
| local-dev-kg/WebGoat | main | Unassigned | 3 days ago | ⋯ | |
| local-dev-kg/DVWA | master | Unassigned | 9 days ago | ⋯ | |
| local-dev-kg/dvws-node | master | Unassigned | Never scanned | ⋯ | |
| local-dev-kg/NodeGoat | master | Unassigned | 11 days ago | ⋯ | |
| local-dev-kg/railsgoat | master | Unassigned | 14 days ago | ⋯ | |
| local-dev-kg/pygoat | main | Unassigned | 13 days ago | ⋯ | |
| local-dev-kg/crAPI | develop | Unassigned | about 1 month ago | ⋯ | |
| local-dev-kg/VAmPI | master | Unassigned | Never scanned | ⋯ | |
| local-dev-kg/wrongsecrets | master | Unassigned | 25 days ago | ⋯ | |
| local-dev-kg/dvga | master | Unassigned | Never scanned | ⋯ | |
| local-dev-kg/bWAPP | master | Unassigned | Never scanned | ⋯ | |
| local-dev-kg/mutillidae | master | Unassigned | Never scanned | ⋯ |
Scans across all scan types
| Type | Target | Status | Findings | Triggered |
|---|---|---|---|---|
| SAST | local-dev-kg/juice-shopmaster · 19a3054c | Complete | 4 Critical28 High | 12 days agoManualComprehensive |
| SCA | local-dev-kg/juice-shopmaster · 19a3054c | Complete | 18 Critical28 High | 12 days agoManualComprehensive |
| SAST | local-dev-kg/bc-kotlinmain · 27f05751 | Complete | 4 High | 12 days agoManualComprehensive |
| SCA | local-dev-kg/cxfmain · 5a501cd8 | Complete | 6 Critical16 High | 12 days agoManualFast |
Static Application Security Testing scan runs
| Repository & Context | Status | Findings | Triggered | Language |
|---|---|---|---|---|
local-dev-kg/bc-kotlinmain · 27f05751 | Complete | 4 High | 12 days agoManualComprehensive | Kotlin |
local-dev-kg/bc-csharpmaster · 5200dfdf | Complete | 27 High10 Medium | 12 days agoManualComprehensive | C# |
local-dev-kg/juice-shopmaster · 19a3054c | Complete | 4 Critical28 High | 12 days agoManualComprehensive | JS |
local-dev-kg/pipline-test-repomain · 8524e5fb | Complete | 9 Critical10 High | 18 days agoManualComprehensive | JS |
local-dev-kg/driftmain · f329b1ab | Complete | 1 Critical4 High | 18 days agoManualComprehensive | Ruby |
local-dev-kg/pipline-test-repomain · 8524e5fb | Complete | 10 Critical9 High | 18 days agoManualComprehensive | JS |
local-dev-kg/driftmain · f329b1ab | Complete | 1 Critical2 High | 18 days agoManualComprehensive | Ruby |
local-dev-kg/driftmain · f329b1ab | Complete | 1 Critical2 High | 18 days agoManualComprehensive | Ruby |
Software Composition Analysis scan runs
| Repository & Context | Status | Findings | Triggered |
|---|---|---|---|
local-dev-kg/bc-kotlinmain · 27f05751 | Complete | 1 Medium | 12 days agoManualComprehensive |
local-dev-kg/bc-csharpmaster · 5200dfdf | Complete | 3 Medium | 12 days agoManualComprehensive |
local-dev-kg/cxfmain · 5a501cd8 | Complete | 6 Critical16 High | 12 days agoManualFast |
test/vectormaster · 47b5b02b | Complete | 5 Critical11 High | 12 days agoManualComprehensive |
test/grafanamain · a4dbaa56 | Complete | 1 Critical8 High | 12 days agoManualFast |
test/vuln-bankmain · 9b22a832 | Complete | 6 High14 Medium | 12 days agoManualComprehensive |
local-dev-kg/juice-shopmaster · 19a3054c | Complete | 18 Critical28 High | 12 days agoManualComprehensive |
local-dev-kg/driftmain · f329b1ab | Complete | 2 Critical7 High | 18 days agoManualComprehensive |
| Finding | Data Flow | Boundaries | Teams | Severity |
|---|---|---|---|---|
CWE-643: XPath Operator Injection via JSON-parsed URL parameter in Sequelize WHERE clause | recycles.ts:34 (col 21) | juice-shop | engineering | HIGH |
CWE-89: SQL Injection via unverified email field in login query | login.ts:34 → login.ts:55 | juice-shop | engineering | HIGH |
CWE-209: XSS via unverified URL controlled URL in profile-image fetch | profileImageUrlUpload.ts:13 → profileImageUrlUpload.ts:16 | juice-shop | engineering | HIGH |
CWE-943: NoSQL Injection via unverified request body ID in MongoDB query | b2bOrder.ts:30 → b2bOrder.ts:35 | juice-shop | engineering | HIGH |
CWE-943: NoSQL Injection via unverified request body ID in MongoDB query | b2bOrder.ts:30 → b2bOrder.ts:39 | juice-shop | engineering | HIGH |
CWE-943: NoSQL Injection via unverified request body in MongoDB query filter | b2bOrder.ts:30 → b2bOrder.ts:42 | juice-shop | engineering | HIGH |
CWE-22: Path Traversal via unverified request body file in fileRead | verifyFiles.ts:9 → verifyFiles.ts:24 | juice-shop | engineering | HIGH |
CWE-502: Unsafe deserialization via user-controlled file path in fs.read | payment.component.ts:11 → payment.component.ts:18 | juice-shop | engineering | HIGH |
CWE-89: SQL Injection via unverified search parameter in raw Sequelize query | search.ts:13 → search.ts:18 | juice-shop | engineering | HIGH |
| Finding | Location | Boundaries | Teams | Severity |
|---|---|---|---|---|
CWE-347: JWT Token Decoded Without Signature Verification | app.guard.ts:18 | juice-shop | engineering | CRITICAL |
CWE-310: SQL Injection in Authentication Query Leading to Cleartext Password Transmission | login/loginUserChallenge_4.ts:15 | juice-shop | engineering | CRITICAL |
CWE-548: Directory Listing Exposure - (well-known Directory) | directoryListing/dirIndex_4.ts:0 | juice-shop | engineering | HIGH |
CWE-1004: Insufficient Random Password Generation Using Base64 Encoding of Reversed Email | auth/component_2.ts:18 | juice-shop | engineering | HIGH |
CWE-328: Use of Weak Hash Function (Base64) for Password Generation | auth/component_3.ts:18 | juice-shop | engineering | HIGH |
CWE-614: Authentication Token Cookie Missing Secure Flag | payment.component.ts:11 | juice-shop | engineering | HIGH |
CWE-614: Authentication Token Cookie Missing Secure Flag | two-factor-auth-enter.component.ts:14 | juice-shop | engineering | HIGH |
CWE-327: Weak HMAC Secret Key - Hardcoded For 2FA Authentication | 2fa/totp_5.ts:5 | juice-shop | engineering | HIGH |
CWE-326: Hardcoded RSA Private Key in Source Code | cryptUtils.ts:14 | juice-shop | engineering | HIGH |
CWE-693: Predictable RSA Private Key for Security Sensitive Data | cryptUtils.ts:18 | juice-shop | engineering | HIGH |
CWE-565: Missing CSRF Protection on State-Changing Endpoint Verdict Acknowledgment | checkVerdict.ts:25 | juice-shop | engineering | HIGH |
CWE-213: excessive-data-exposure in routes/authenticatedUsers.ts:25 | authenticatedUsers.ts:25:0 | juice-shop | engineering | HIGH |
CWE-20: missing-input-validation in routes/b2bOrder.ts:19 | b2bOrder.ts:19:0 | juice-shop | engineering | HIGH |
CWE-770: missing-rate-limit in routes/search.ts:23 | search.ts:23:0 | juice-shop | engineering | HIGH |
CWE-770: missing-rate-limit in routes/b2bOrder.ts:17 | b2bOrder.ts:17:0 | juice-shop | engineering | HIGH |
CWE-770: missing-rate-limit in routes/chatbot.ts:205 | chatbot.ts:205:0 | juice-shop | engineering | HIGH |
CWE-770: missing-rate-limit in routes/dataExports.ts:16 | dataExports.ts:16:0 | juice-shop | engineering | HIGH |
CWE-770: missing-rate-limit in routes/search.ts:23 | search.ts:23:0 | juice-shop | engineering | HIGH |
CWE-639: bola in routes/basket.ts:0 | basket.ts:0 | juice-shop | engineering | HIGH |
CWE-915: mass-assignment in server.ts:0 | server.ts:0 | juice-shop | engineering | HIGH |
CWE-269: privesc in server.ts:0 | server.ts:0 | juice-shop | engineering | HIGH |
| Finding | Data Flow | Boundaries | Teams | Severity |
|---|---|---|---|---|
CWE-287: Authentication Bypass in changeProduct | server.ts:0 → server.ts:0 | juice-shop | engineering | CRITICAL |
CWE-287: Authentication Bypass in changePassword | changePassword.ts:0 → changePassword.ts:0 | juice-shop | engineering | HIGH |
CWE-287: Authentication Bypass in updateProductReview | updateProductReviews.ts:0 → updateProductReviews.ts:0 | juice-shop | engineering | HIGH |
CWE-285: Authorization Bypass in orderHistory | orderHistory.ts:0 → orderHistory.ts:0 | juice-shop | engineering | HIGH |
CWE-287: Authentication Bypass in collectorWebReader | recyclewebreader.ts:0 → recyclewebreader.ts:0 | juice-shop | engineering | HIGH |
CWE-287: Authentication Bypass in serviceFlow | services.ts:0 → services.ts:0 | juice-shop | engineering | HIGH |
CWE-287: Authentication Bypass in deliveryService | deliveryMethod.ts:0 → deliveryMethod.ts:0 | juice-shop | engineering | HIGH |
CWE-639: Insecure Direct Object Reference in trackOrder | trackOrder.ts:0 → trackOrder.ts:0 | juice-shop | engineering | HIGH |
CWE-639: Insecure Direct Object Reference in couponCheck | couponcheck.ts:0 → couponcheck.ts:0 | juice-shop | engineering | HIGH |
CWE-287: Authentication Bypass in forgotFeedback challenge | feedbackChallenge.ts:0 → feedbackChallenge.ts:0 | juice-shop | engineering | HIGH |
CWE-287: Authentication Bypass in N/A (finds auto-generated) | N/A:0 → N/A:0 | juice-shop | engineering | HIGH |
| Package | Reachability | Dependency | Recommendation | Boundaries | Teams |
|---|---|---|---|---|---|
marsdb@0.6.11 npm | Reachable (1 of 2) | Direct | , | juice-shop | engineering |
jsonwebtoken@0.4.0 npm | Reachable (2 of 4) | Direct | cd appsec/scans/appsec-ba… | juice-shop | engineering |
vm2@3.9.17 npm | Reachable (1 of 5) | Transitive | cd appsec/scans/appsec-ba… | , | , |
express-jwt@0.1.3 npm | Reachable | Direct | cd appsec/scans/appsec-ba… | juice-shop | engineering |
sanitize-html@1.4.2 npm | Reachable (2 of 7) | Direct | cd appsec/scans/appsec-ba… | juice-shop | engineering |
Update jsonwebtoken from version 0.4.0 to version 4.2.2 or later.
cd appsec/scans/appsec-baseline-scans/8eed4fb4-4809-40b8-9769-f662decd9741/repo && npm install jsonwebtoken@4.2.2
jsonwebtoken@0.4.0 does not validate the JWT algorithm during jwt.verify(), enabling both the alg:none bypass and an RS256→HS256 algorithm confusion attack. The codebase calls jwt.verify(token, publicKey, callback) without an algorithms allowlist in three production files.
jsonwebtoken@0.4.0 is called via jwt.verify() in three production routes without restricting the allowed algorithm. An attacker can craft a forged JWT signed with HS256 using the RSA public key as the HMAC secret, which the library will accept as valid, completely bypassing authentication.
Versions ≤8.5.1 of jsonwebtoken library could be misconfigured so that legacy, insecure key types are used for signature verification.
In versions ≤8.5.1 of jsonwebtoken library, lack of algorithm definition and a falsy secret or key in the jwt.verify() call could lead to signature validation bypass.
| Description | Location | CWE | Severity |
|---|---|---|---|
Hardcoded OAuth 2.0 Access Token Exposure in URL Parameter | frontend/src/app/Services/user.service.ts:60 | CWE-798 | HIGH |
Hardcoded Ethereum Mnemonic Phrase in Source Code | routes/checkKeys.ts:7 | CWE-798 | HIGH |
Hardcoded Alchemy API Key in WebSocket Provider | routes/nftMint.ts:9 | CWE-798 | HIGH |
Hardcoded Alchemy API Key in Production Code | routes/web3Wallet.ts:9 | CWE-798 | HIGH |
Define how many days your team has to remediate vulnerabilities after detection. SLA deadlines appear on each finding and drive the compliance chart on your dashboard.
Repositories and pentest profiles your org is monitoring
| Profile | Env | Target URL | Repos | Scans | Last Scanned | ||
|---|---|---|---|---|---|---|---|
| tmp 2 juice shop | Staging | https://staging.example.com | 1 | 6 | 1 day ago | Scan | ⋯ |
| tmp juice shop | Staging | https://shop.staging.example.com | 1 | 4 | 6 days ago | Scan | ⋯ |
| Juice Shop | Staging | https://demo.example.com | 1 | 8 | 6 days ago | Scan | ⋯ |
| Test | Staging | https://demo.example.com | 1 | 3 | 11 days ago | Scan | ⋯ |
Repositories and pentest profiles your org is monitoring
| Repository | Default Branch | Group | Boundaries | Last Scanned | |||
|---|---|---|---|---|---|---|---|
| local-dev-kg/AWSGoat | master | Unassigned | None | 12 days ago | Scan | ⋯ | |
| local-dev-kg/bc-csharp | master | Unassigned | None | 12 days ago | Scan | ⋯ | |
| local-dev-kg/bc-java | main | Unassigned | None | about 2 months ago | Scan | ⋯ | |
| local-dev-kg/bc-kotlin | main | Unassigned | None | 12 days ago | Scan | ⋯ | |
| local-dev-kg/boundaries-ex | main | Unassigned | 7 boundaries | about 1 month ago | Scan | ⋯ | |
| local-dev-kg/cxf | main | Unassigned | None | 12 days ago | Scan | ⋯ | |
| test/documenso | main | Unassigned | None | Never scanned | Scan | ⋯ | |
| local-dev-kg/drift | main | Unassigned | None | 18 days ago | Scan | ⋯ | |
| local-dev-kg/dvws-node | master | Unassigned | None | Never scanned | Scan | ⋯ | |
| test/elasticsearch | main | Unassigned | None | Never scanned | Scan | ⋯ | |
| local-dev-kg/elasticsearch-test | main | Unassigned | None | Never scanned | Scan | ⋯ |
public · PHP · master