FixVibe

// 漏洞聚焦

What FixVibe checksin AI-built apps.

Security checks for apps built with Lovable, Bolt, v0, Cursor and other AI coding tools: Supabase and Firebase access rules, leaked secrets, security headers and more. 230+ checks run on every URL scan, 130+ more on verified domains and 190+ on connected GitHub repos.

01 / 07

Backend-as-a-Service

02 / 07

密钥

03 / 07

HTTP 与表面

04 / 07

主动探测

严重· CWE-639

跨租户数据泄露

没有租户 ID 强制的多租户 SaaS 会在组织间泄露客户数据。

阅读聚焦 →

严重· CWE-345

JWT alg=none Acceptance

A decoded token is not an authenticated identity.

阅读聚焦 →

严重· CWE-78

操作系统命令注入

当用户输入成为 shell 命令的一部分,shell 就执行攻击者写的任何东西。

阅读聚焦 →

严重· CWE-94

服务端模板注入 (SSTI)

模板引擎把用户输入当作模板时,服务器就把用户输入当作代码。

阅读聚焦 →

严重· CWE-89

SQL 注入

当用户输入成为查询的一部分,数据库就不再属于你。

阅读聚焦 →

高· CWE-287

认证流程缺陷

登录、注册、密码重置——大多数账号接管实际上就发生在这。

阅读聚焦 →

高· CWE-918

盲 SSRF (带外)

如果服务器抓取用户提供的 URL,用户就能让它去抓内部服务。

阅读聚焦 →

高· CWE-942

CORS 配置错误

宽松的 Access-Control-Allow-Origin 加上凭据,意味着你的 API 是所有人的 API。

阅读聚焦 →

高· CWE-79

通过 URL 片段的 DOM 型 XSS

现代 SPA 读取 location.hash 并写入 DOM——攻击者的 payload 一路同行。

阅读聚焦 →

高· CWE-434

文件上传校验

用户上传的文件是任意字节——不检查就当“图片”接受是在邀请 RCE。

阅读聚焦 →

高· CWE-770

GraphQL 深度轰炸和批量绕过

GraphQL 的灵活性也是它的脆弱点——深度炸弹、别名批处理、字段建议泄露。

阅读聚焦 →

高· CWE-444

HTTP 请求走私

前端代理和后端对一个请求在哪结束意见不一致——攻击者就在缝隙间穿行。

阅读聚焦 →

高· CWE-639

IDOR / BOLA

如果你的 API 信任客户端发送正确的 ID,客户端就能发送任何 ID。

阅读聚焦 →

高· CWE-77

LLM 提示注入

如果你的 AI 功能把用户输入当作指令信任,用户就能改写系统提示。

阅读聚焦 →

高· CWE-943

NoSQL 操作符注入

用户控制的 JSON 中的 MongoDB 风格操作符把你的查询变成通配符。

阅读聚焦 →

高· CWE-79

反射型跨站脚本攻击 (XSS)

无声的劫持:一个未经处理的参数就能在你用户的浏览器里执行攻击者代码。

阅读聚焦 →

高· CWE-611

XML 外部实体 (XXE)

如果你的 XML 解析器解析外部实体,你的服务器就在为攻击者读文件。

阅读聚焦 →

中· CWE-203

账号枚举

如果登录在邮箱存在与否时返回不同响应,攻击者就能构建客户名单。

阅读聚焦 →

中· CWE-113

CRLF / 响应拆分

如果用户输入落入响应头,换行符让攻击者写入自己的头部。

阅读聚焦 →

中· CWE-352

CSRF 防护

如果你的状态变更端点不要求 CSRF token,第三方网站就能以你的用户身份行动。

阅读聚焦 →

中· CWE-307

缺失速率限制

认证端点没有速率限制,攻击者可以以线路速度做凭据填充。

阅读聚焦 →

中· CWE-693

Next.js Header Configuration Drift

Headers set on `/` do not always protect nested routes.

阅读聚焦 →

中· CWE-601

开放重定向

你那个不验证目的地的 /redirect?url=… 就是个钓鱼套件。

阅读聚焦 →

严重· CWE-94 / CWE-502

ChromaDB Python Backend RCE Advisory

A self-hosted ChromaDB on the Python backend can run attacker code before login.

阅读聚焦 →

05 / 07

源代码

高· CWE-798

Committed AI-Generated Secrets

AI snippets should not ship provider keys into git.

阅读聚焦 →

高· CWE-94

高风险源码模式

eval()、dangerouslySetInnerHTML、硬编码密钥——SAST 抓了 25 年的模式。

阅读聚焦 →

高· CWE-284

Supabase RLS in Migrations

A public table without RLS is a future data leak.

阅读聚焦 →

高· CWE-1395

易受攻击的依赖

你的 package-lock.json 包含数千个包。其中一些有已知 CVE。

阅读聚焦 →

高· CWE-345

Webhook 签名验证

如果你的 webhook handler 不验证签名,任何人都能伪造事件。

阅读聚焦 →

中· CWE-693

AI-Generated Code Guardrails

Fast AI-assisted changes need repo-level security rails.

阅读聚焦 →

中· CWE-1357

代码仓库安全卫生

分支保护、Action pin、密钥卫生——你怎么管理仓库比代码本身更重要。

阅读聚焦 →

严重· CWE-78

AVideo Command Injection Advisory

An outdated AVideo Composer dependency can expose video-link import paths to command execution risk.

阅读聚焦 →

严重· CWE-1321

deephas Prototype-Pollution Advisory

A vulnerable deephas dependency can put deep-path object handling on a prototype-pollution path.

阅读聚焦 →

严重· CWE-89

Ghost Content API SQL Injection Advisory

A vulnerable Ghost dependency can put public content APIs on the database boundary.

阅读聚焦 →

严重· CWE-89

LiteLLM SQL Injection Advisory

A vulnerable LiteLLM Proxy version can turn API-key verification into database exposure.

阅读聚焦 →

严重· CWE-94

NLTK Zip Slip Code Execution Advisory

A vulnerable NLTK downloader can turn compromised package archives into filesystem writes and code-execution risk.

阅读聚焦 →

严重· CWE-506

TanStack ArkType Adapter Malware Advisory

Known malicious npm package versions can put CI and developer secrets at install-time risk.

阅读聚焦 →

严重· CWE-913

vm2 Sandbox Breakout Advisory

A vulnerable JavaScript sandbox dependency can put untrusted-code boundaries at risk.

阅读聚焦 →

高· CWE-506

Compromised codfish GitHub Action

Release workflows should not keep pointing at compromised Action refs.

阅读聚焦 →

高· CWE-862

Gitea Composer Source-Link Permission Advisory

Pinned affected Gitea server images need a deployment upgrade.

阅读聚焦 →

高· CWE-22

Gogs Directory Traversal Dependency Advisory

An affected Gogs runtime can put file-upload path handling on a traversal boundary.

阅读聚焦 →

高· CWE-22

Gradio Windows Python Path Traversal Advisory

Gradio apps served from Windows on Python 3.13+ can leak files the app process can read.

阅读聚焦 →

高· CWE-918

Next.js WebSocket SSRF Dependency Advisory

Affected self-hosted Next.js servers need a framework upgrade.

阅读聚焦 →

高· CWE-754

PDF.js JavaScript Execution Advisory

A vulnerable PDF viewer can turn a malicious document into script execution.

阅读聚焦 →

高· CWE-755

PickleScan ZIP CRC Bypass Advisory

A vulnerable PickleScan dependency can miss malicious model archives when scans fail open.

阅读聚焦 →

高· CWE-476

ws Excessive-Header DoS Advisory

Affected ws server runtimes can crash when upgrade requests carry too many headers.

阅读聚焦 →

06 / 07

探索

07 / 07

DNS

Find out which of these your app has: paste its URL for a free preview.

运行扫描 →
Security Checks for AI-Built Apps: Supabase, Firebase, Secrets · FixVibe