Results for "IDOR"
- Article
Business Logic Is AppSec’s Unsolved Problem
Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the g…
- Article
Why Static Analysis Struggles with Business Logic Vulnerabilities
The gap between tracking where data flows and reasoning about whether the logic is correct.
- Article
How Broken Access Controls in Cal.com Leaked Millions of Bookings and Enabled Complete Account Takeover
Gecko’s AI security engineer discovered critical chained vulnerabilities in Cal.com Cloud that allowed complete account takeover and exposed all booking data.
- Article
How Gecko Discovered 30 0-Day Vulnerabilities No AppSec Tool Found
Previously, there were entire classes of business logic and multi-step vulnerabilities that have long been invisible to SAST. Today, that changes.
- Article
CVE-2025-53944: AutoGPT Authorization Bypass in Graph Execution External API
Authorization bypass vulnerability in AutoGPT’s external API allowing authenticated users to access execution results from other users’ graph executions.
- Article
n8n Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
Authorization bypass in n8n’s dynamic-credentials OAuth endpoints allows any authenticated user to operate on another user’s OAuth credential by supplying its I…
Showing 11 - 16 of 16 results