// vulnerability spotlight
What FixVibe checksin AI-built apps.
Security checks for apps built with Lovable, Bolt, v0, Cursor and other AI coding tools: Supabase and Firebase access rules, leaked secrets, security headers and more. 230+ checks run on every URL scan, 130+ more on verified domains and 190+ on connected GitHub repos.
01 / 07
Backend-as-a-Service
Firebase Security Rules
`allow read, write: if true` is somebody's production database right now.
Spotlight’ı oku →
Supabase Row-Level Security
Without RLS on every public table, your anon key is a license to read anything.
Spotlight’ı oku →
Clerk & Auth0 Configuration
Identity providers leak more than they should when defaults aren't tightened.
Spotlight’ı oku →
Supabase Storage and API Posture
Public buckets and anon-listable objects are where BaaS data leaks start.
Spotlight’ı oku →
02 / 07
Secrets
Secrets in JavaScript Bundles
If it shipped in your client bundle, it's not a secret — it's a publication.
Spotlight’ı oku →
JWT Integrity (alg confusion, weak secrets)
If your JWT verifier trusts the token's own header, it will believe whatever the attacker types.
Spotlight’ı oku →
Tokens in Browser Storage
localStorage is JavaScript-readable. Auth tokens stored there are XSS-stealable by design.
Spotlight’ı oku →
Exposed Source Maps
If your .map files are public, the attacker is reading your TypeScript.
Spotlight’ı oku →
Information Leakage in JavaScript
Internal API hosts, version banners, and TODO comments — small leaks add up to a map of your stack.
Spotlight’ı oku →
03 / 07
HTTP ve yüzey
Session Cookie Attributes
HttpOnly, Secure, SameSite — three flags that turn a session cookie into something attackers can't easily steal.
Spotlight’ı oku →
HTTP Security Headers
Headers are free defense — most apps still ship without them.
Spotlight’ı oku →
TLS Configuration
Old cipher suites plus missing HSTS equals a hostile WiFi away from session hijack.
Spotlight’ı oku →
Vercel Deployment Protection
Generated deployment URLs should not become public staging doors.
Spotlight’ı oku →
04 / 07
Aktif problar
Cross-Tenant Data Leaks
Multi-tenant SaaS without tenant ID enforcement leaks customer data across orgs.
Spotlight’ı oku →
JWT alg=none Acceptance
A decoded token is not an authenticated identity.
Spotlight’ı oku →
OS Command Injection
When user input becomes part of a shell command, the shell runs whatever the attacker writes.
Spotlight’ı oku →
Server-Side Template Injection (SSTI)
When a template engine treats user input as a template, the server treats user input as code.
Spotlight’ı oku →
SQL Injection
When user input becomes part of a query, the database stops being yours.
Spotlight’ı oku →
Auth Flow Defects
Login, signup, and password reset are where most account takeovers actually happen.
Spotlight’ı oku →
Blind SSRF (Out-of-Band)
If the server fetches user-supplied URLs, the user can make it fetch internal services.
Spotlight’ı oku →
CORS Misconfiguration
Permissive Access-Control-Allow-Origin plus credentials means your API is everyone's API.
Spotlight’ı oku →
DOM-based XSS via URL Fragment
Modern SPAs read location.hash and write it into the DOM — attacker payloads ride along.
Spotlight’ı oku →
File Upload Validation
User-uploaded files are arbitrary bytes — accepting them as 'images' without checking is asking for RCE.
Spotlight’ı oku →
GraphQL Depth Bombing & Batch Bypass
GraphQL's flexibility is also its vulnerability — depth bombs, alias batching, and field-suggestion leaks.
Spotlight’ı oku →
HTTP Request Smuggling
Front-end proxy and back-end disagree on where one request ends — attacker rides the seam.
Spotlight’ı oku →
IDOR / BOLA
If your API trusts the client to send the correct ID, the client can send any ID.
Spotlight’ı oku →
LLM Prompt Injection
If your AI feature trusts user input as instruction, the user can rewrite the system prompt.
Spotlight’ı oku →
NoSQL Operator Injection
MongoDB-style operators in user-controlled JSON turn your query into a wildcard.
Spotlight’ı oku →
Reflected Cross-Site Scripting (XSS)
The silent hijack: when a single unsanitized parameter executes attacker code in your users' browsers.
Spotlight’ı oku →
XML External Entity (XXE)
If your XML parser resolves external entities, your server reads files for the attacker.
Spotlight’ı oku →
Account Enumeration
If your login responds differently when the email exists vs doesn't, attackers can build a customer list.
Spotlight’ı oku →
CRLF / Response Splitting
If user input lands in a response header, line breaks let the attacker write their own headers.
Spotlight’ı oku →
CSRF Protection
If your state-changing endpoints don't require a CSRF token, third-party sites can act as your users.
Spotlight’ı oku →
Missing Rate Limiting
Without rate limits on auth endpoints, the attacker can credential-stuff at line speed.
Spotlight’ı oku →
Next.js Header Configuration Drift
Headers set on `/` do not always protect nested routes.
Spotlight’ı oku →
Open Redirect
Your /redirect?url=… that doesn't validate the destination is a phishing kit.
Spotlight’ı oku →
ChromaDB Python Backend RCE Advisory
A self-hosted ChromaDB on the Python backend can run attacker code before login.
Spotlight’ı oku →
05 / 07
Kaynak kod
Committed AI-Generated Secrets
AI snippets should not ship provider keys into git.
Spotlight’ı oku →
Risky Source-Code Patterns
eval(), dangerouslySetInnerHTML, hard-coded secrets — the patterns SAST has been catching for 25 years.
Spotlight’ı oku →
Supabase RLS in Migrations
A public table without RLS is a future data leak.
Spotlight’ı oku →
Vulnerable Dependencies
Your package-lock.json includes thousands of packages. Some have known CVEs.
Spotlight’ı oku →
Webhook Signature Verification
If your webhook handler doesn't verify the signature, anyone can forge events.
Spotlight’ı oku →
AI-Generated Code Guardrails
Fast AI-assisted changes need repo-level security rails.
Spotlight’ı oku →
Repo Security Hygiene
Branch protection, action pinning, secret hygiene — how your repo is run matters more than the code.
Spotlight’ı oku →
AVideo Command Injection Advisory
An outdated AVideo Composer dependency can expose video-link import paths to command execution risk.
Spotlight’ı oku →
deephas Prototype-Pollution Advisory
A vulnerable deephas dependency can put deep-path object handling on a prototype-pollution path.
Spotlight’ı oku →
Ghost Content API SQL Injection Advisory
A vulnerable Ghost dependency can put public content APIs on the database boundary.
Spotlight’ı oku →
LiteLLM SQL Injection Advisory
A vulnerable LiteLLM Proxy version can turn API-key verification into database exposure.
Spotlight’ı oku →
NLTK Zip Slip Code Execution Advisory
A vulnerable NLTK downloader can turn compromised package archives into filesystem writes and code-execution risk.
Spotlight’ı oku →
TanStack ArkType Adapter Malware Advisory
Known malicious npm package versions can put CI and developer secrets at install-time risk.
Spotlight’ı oku →
vm2 Sandbox Breakout Advisory
A vulnerable JavaScript sandbox dependency can put untrusted-code boundaries at risk.
Spotlight’ı oku →
Compromised codfish GitHub Action
Release workflows should not keep pointing at compromised Action refs.
Spotlight’ı oku →
Gitea Composer Source-Link Permission Advisory
Pinned affected Gitea server images need a deployment upgrade.
Spotlight’ı oku →
Gogs Directory Traversal Dependency Advisory
An affected Gogs runtime can put file-upload path handling on a traversal boundary.
Spotlight’ı oku →
Gradio Windows Python Path Traversal Advisory
Gradio apps served from Windows on Python 3.13+ can leak files the app process can read.
Spotlight’ı oku →
Next.js WebSocket SSRF Dependency Advisory
Affected self-hosted Next.js servers need a framework upgrade.
Spotlight’ı oku →
PDF.js JavaScript Execution Advisory
A vulnerable PDF viewer can turn a malicious document into script execution.
Spotlight’ı oku →
PickleScan ZIP CRC Bypass Advisory
A vulnerable PickleScan dependency can miss malicious model archives when scans fail open.
Spotlight’ı oku →
ws Excessive-Header DoS Advisory
Affected ws server runtimes can crash when upgrade requests carry too many headers.
Spotlight’ı oku →
06 / 07
Discovery
CVE Cross-Reference
Detected version + public CVE database = a list of attacks already documented.
Spotlight’ı oku →
Debug & Admin Endpoints
Debug consoles and admin panels that should never be reachable from the internet.
Spotlight’ı oku →
Exposed Files & Backup Directories
.env, .git, .DS_Store, backup.sql — files that should never be public, accidentally are.
Spotlight’ı oku →
Cloudflare Origin & Proxy Posture
If your origin IP is discoverable, Cloudflare's WAF is bypassable.
Spotlight’ı oku →
GraphQL Introspection Exposed
Introspection in production hands the attacker your full type system.
Spotlight’ı oku →
Threat-Intel Cross-Reference
Spamhaus DBL, URLhaus — your domain's reputation, externally seen.
Spotlight’ı oku →
Exposed API Documentation
Public Swagger and OpenAPI docs are an API map for you and for the attacker.
Spotlight’ı oku →
Netlify-Specific Exposure
Netlify deploy preview URLs, x-nf-* headers, _redirects mistakes.
Spotlight’ı oku →
Privacy & Cookie Compliance Markers
GDPR-required pages — present and linked, or you're at risk of a complaint.
Spotlight’ı oku →
Technology Fingerprinting
Knowing your stack is half the recon — outdated frameworks turn that into the other half.
Spotlight’ı oku →
Vercel-Specific Exposure
_next/static, x-vercel-* headers, preview URLs — Vercel-isms that leak more than they should.
Spotlight’ı oku →
07 / 07
