FixVibe

// 漏洞聚焦

What FixVibe checksin AI-built apps.

Security checks for apps built with Lovable, Bolt, v0, Cursor and other AI coding tools: Supabase and Firebase access rules, leaked secrets, security headers and more. 230+ checks run on every URL scan, 130+ more on verified domains and 190+ on connected GitHub repos.

01 / 07

Backend-as-a-Service

02 / 07

密钥

03 / 07

HTTP 與表面

04 / 07

主動探測

严重· CWE-639

Cross-Tenant Data Leaks

Multi-tenant SaaS without tenant ID enforcement leaks customer data across orgs.

阅讀聚焦 →

严重· CWE-345

JWT alg=none Acceptance

A decoded token is not an authenticated identity.

阅讀聚焦 →

严重· CWE-78

OS Command Injection

When user input becomes part of a shell command, the shell runs whatever the attacker writes.

阅讀聚焦 →

严重· CWE-94

Server-Side Template Injection (SSTI)

When a template engine treats user input as a template, the server treats user input as code.

阅讀聚焦 →

严重· CWE-89

SQL Injection

When user input becomes part of a query, the database stops being yours.

阅讀聚焦 →

高· CWE-287

Auth Flow Defects

Login, signup, and password reset are where most account takeovers actually happen.

阅讀聚焦 →

高· CWE-918

Blind SSRF (Out-of-Band)

If the server fetches user-supplied URLs, the user can make it fetch internal services.

阅讀聚焦 →

高· CWE-942

CORS Misconfiguration

Permissive Access-Control-Allow-Origin plus credentials means your API is everyone's API.

阅讀聚焦 →

高· CWE-79

DOM-based XSS via URL Fragment

Modern SPAs read location.hash and write it into the DOM — attacker payloads ride along.

阅讀聚焦 →

高· CWE-434

File Upload Validation

User-uploaded files are arbitrary bytes — accepting them as 'images' without checking is asking for RCE.

阅讀聚焦 →

高· CWE-770

GraphQL Depth Bombing & Batch Bypass

GraphQL's flexibility is also its vulnerability — depth bombs, alias batching, and field-suggestion leaks.

阅讀聚焦 →

高· CWE-444

HTTP Request Smuggling

Front-end proxy and back-end disagree on where one request ends — attacker rides the seam.

阅讀聚焦 →

高· CWE-639

IDOR / BOLA

If your API trusts the client to send the correct ID, the client can send any ID.

阅讀聚焦 →

高· CWE-77

LLM Prompt Injection

If your AI feature trusts user input as instruction, the user can rewrite the system prompt.

阅讀聚焦 →

高· CWE-943

NoSQL Operator Injection

MongoDB-style operators in user-controlled JSON turn your query into a wildcard.

阅讀聚焦 →

高· CWE-79

Reflected Cross-Site Scripting (XSS)

The silent hijack: when a single unsanitized parameter executes attacker code in your users' browsers.

阅讀聚焦 →

高· CWE-611

XML External Entity (XXE)

If your XML parser resolves external entities, your server reads files for the attacker.

阅讀聚焦 →

中· CWE-203

Account Enumeration

If your login responds differently when the email exists vs doesn't, attackers can build a customer list.

阅讀聚焦 →

中· CWE-113

CRLF / Response Splitting

If user input lands in a response header, line breaks let the attacker write their own headers.

阅讀聚焦 →

中· CWE-352

CSRF Protection

If your state-changing endpoints don't require a CSRF token, third-party sites can act as your users.

阅讀聚焦 →

中· CWE-307

Missing Rate Limiting

Without rate limits on auth endpoints, the attacker can credential-stuff at line speed.

阅讀聚焦 →

中· CWE-693

Next.js Header Configuration Drift

Headers set on `/` do not always protect nested routes.

阅讀聚焦 →

中· CWE-601

Open Redirect

Your /redirect?url=… that doesn't validate the destination is a phishing kit.

阅讀聚焦 →

严重· CWE-94 / CWE-502

ChromaDB Python Backend RCE Advisory

A self-hosted ChromaDB on the Python backend can run attacker code before login.

阅讀聚焦 →

05 / 07

源代码

高· CWE-798

Committed AI-Generated Secrets

AI snippets should not ship provider keys into git.

阅讀聚焦 →

高· CWE-94

Risky Source-Code Patterns

eval(), dangerouslySetInnerHTML, hard-coded secrets — the patterns SAST has been catching for 25 years.

阅讀聚焦 →

高· CWE-284

Supabase RLS in Migrations

A public table without RLS is a future data leak.

阅讀聚焦 →

高· CWE-1395

Vulnerable Dependencies

Your package-lock.json includes thousands of packages. Some have known CVEs.

阅讀聚焦 →

高· CWE-345

Webhook Signature Verification

If your webhook handler doesn't verify the signature, anyone can forge events.

阅讀聚焦 →

中· CWE-693

AI-Generated Code Guardrails

Fast AI-assisted changes need repo-level security rails.

阅讀聚焦 →

中· CWE-1357

Repo Security Hygiene

Branch protection, action pinning, secret hygiene — how your repo is run matters more than the code.

阅讀聚焦 →

严重· CWE-78

AVideo Command Injection Advisory

An outdated AVideo Composer dependency can expose video-link import paths to command execution risk.

阅讀聚焦 →

严重· CWE-1321

deephas Prototype-Pollution Advisory

A vulnerable deephas dependency can put deep-path object handling on a prototype-pollution path.

阅讀聚焦 →

严重· CWE-89

Ghost Content API SQL Injection Advisory

A vulnerable Ghost dependency can put public content APIs on the database boundary.

阅讀聚焦 →

严重· CWE-89

LiteLLM SQL Injection Advisory

A vulnerable LiteLLM Proxy version can turn API-key verification into database exposure.

阅讀聚焦 →

严重· CWE-94

NLTK Zip Slip Code Execution Advisory

A vulnerable NLTK downloader can turn compromised package archives into filesystem writes and code-execution risk.

阅讀聚焦 →

严重· CWE-506

TanStack ArkType Adapter Malware Advisory

Known malicious npm package versions can put CI and developer secrets at install-time risk.

阅讀聚焦 →

严重· CWE-913

vm2 Sandbox Breakout Advisory

A vulnerable JavaScript sandbox dependency can put untrusted-code boundaries at risk.

阅讀聚焦 →

高· CWE-506

Compromised codfish GitHub Action

Release workflows should not keep pointing at compromised Action refs.

阅讀聚焦 →

高· CWE-862

Gitea Composer Source-Link Permission Advisory

Pinned affected Gitea server images need a deployment upgrade.

阅讀聚焦 →

高· CWE-22

Gogs Directory Traversal Dependency Advisory

An affected Gogs runtime can put file-upload path handling on a traversal boundary.

阅讀聚焦 →

高· CWE-22

Gradio Windows Python Path Traversal Advisory

Gradio apps served from Windows on Python 3.13+ can leak files the app process can read.

阅讀聚焦 →

高· CWE-918

Next.js WebSocket SSRF Dependency Advisory

Affected self-hosted Next.js servers need a framework upgrade.

阅讀聚焦 →

高· CWE-754

PDF.js JavaScript Execution Advisory

A vulnerable PDF viewer can turn a malicious document into script execution.

阅讀聚焦 →

高· CWE-755

PickleScan ZIP CRC Bypass Advisory

A vulnerable PickleScan dependency can miss malicious model archives when scans fail open.

阅讀聚焦 →

高· CWE-476

ws Excessive-Header DoS Advisory

Affected ws server runtimes can crash when upgrade requests carry too many headers.

阅讀聚焦 →

06 / 07

探索

07 / 07

DNS

Find out which of these your app has: paste its URL for a free preview.

執行掃描 →
Security Checks for AI-Built Apps: Supabase, Firebase, Secrets · FixVibe