Neo reads the diff with the whole repository as context, runs the exploit in a preview build, and posts the proof as a review comment. Push the fix and the same exploit runs again.
acme/apipriya-n wants to merge 3 commits into main from feat/invoice-export
org_id is never checked against the session, so any signed-in user can export another tenant’s invoices.
pr-4821.preview.acme.dev, built from a41f9e2.
Logged in through the browser as org_1042 with the test account from the secret store.
acme/apipriya-n wants to merge 4 commits into main from feat/invoice-export
One tenant reads another tenant’s records by swapping an identifier.
Change an ID in the path and read another user’s resource.
Call the final endpoint without the steps before it and get an approved outcome.
The UI hides the control. The backend still accepts the request.
Parallel requests slip past single-use and balance checks.
Modify price or quantity in the request and still complete checkout.
We use tools on this site to collect and record your data (e.g., your searches), which we and our vendors may use to provide, improve, and personalize our offerings, make recommendations, and for analytics and marketing. Some of these tools identify visitors and link website activity to business contact and company information so we can better understand interest in our services and tailor our outreach. We may share your data with third parties, such as advertising vendors, social media companies, and research partners, which may be "targeted advertising," "selling," or "sharing" under applicable privacy laws. Continuing to browse our site means you accept these terms and our Privacy Policy. To opt out, click the Your Privacy Choices link in the footer.