You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Mixed async styles (callbacks + async/await in file)
src/controller/index.js
~148
28
No body size limit on express.json()
app.js
~19
29
X-Powered-By header not removed
app.js
~16
30
console.error used for normal informational logging
src/controller/index.js
~51, ~120
About
Intentionally vulnerable Node.js REST API for benchmarking SAST, SCA, and code quality tools. Contains 30 real, functional issues across Critical/High/Medium/Low severities covering SQL injection, command injection, path traversal, IDOR, hardcoded secrets, and more. Not for production use.