▸case-01 Review this Python snippet for a web application and provide a structured security audit report: `cursor.execute("SELECT * FROM users WHERE username = '" + user_input + "'")`. Some developers suggest switching to a NoSQL database to avoid this entirely. What is the standard remediation for this specific code? | fail→fail | 11,583 | 16,274 | +40% | 1 | 1 | 0% | 2,067 | 1,154 | -44% | 0 | 0 | — |
▸case-02 Generate a security audit report for this React component: `<div dangerouslySetInnerHTML={{ __html: props.userData }} />`. A junior developer suggested writing a custom regex to strip out `<script>` tags. Provide the industry-standard remediation. | pass→fail | 13,340 | 11,926 | -11% | 1 | 1 | 0% | 2,403 | 2,401 | -0% | 0 | 0 | — |
▸case-03 Provide a vulnerability assessment for a Java application using `ObjectInputStream` to read serialized user data from a network socket. The team wants to just encrypt the stream to secure it. What is the actual vulnerability and proper remediation? | pass→pass | 14,747 | 12,759 | -13% | 1 | 1 | 0% | 2,479 | 2,382 | -4% | 0 | 0 | — |
▸case-04 Audit this Express.js endpoint: `app.get('/transfer', (req, res) => { transferFunds(req.query.amount); })`. The team proposes changing the HTTP method to POST to secure it. Detail the necessary remediation in a structured report. | fail→pass | 32,742 | 18,169 | -45% | 1 | 1 | 0% | 3,396 | 3,854 | +13% | 0 | 0 | — |
▸case-05 Review this Python code using `lxml` to parse incoming XML payloads from an external API: `etree.parse(user_xml)`. The proposed fix is to validate the XML against a strict XSD schema. Provide the correct security remediation. | fail→pass | 9,184 | 18,391 | +100% | 1 | 1 | 0% | 1,666 | 2,667 | +60% | 0 | 0 | — |
▸case-06 Generate a security report for a Node.js script containing `const AWS_SECRET = 'AKIAIOSFODNN7EXAMPLE';`. The developer wants to obfuscate the string using Base64 encoding. What is the standard enterprise remediation? | pass→pass | 12,814 | 12,411 | -3% | 1 | 1 | 0% | 1,408 | 1,447 | +3% | 0 | 0 | — |
▸case-07 Audit this Node.js snippet: `fs.readFile(path.join('/var/www/html', req.query.file), ...)`. The team suggests blocking any input containing '..'. Provide the robust remediation strategy. | pass→pass | 14,103 | 15,742 | +12% | 1 | 1 | 0% | 2,492 | 2,407 | -3% | 0 | 0 | — |
▸case-08 Review this Go service that fetches an image from a user-provided URL: `http.Get(userInputUrl)`. The team plans to block requests to 'localhost' and '127.0.0.1'. Detail the comprehensive remediation in an audit report. | fail→fail | 21,115 | 27,547 | +30% | 1 | 1 | 0% | 4,211 | 5,633 | +34% | 0 | 0 | — |
▸case-09 Provide a security assessment for this Express endpoint: `app.get('/api/receipts/:id', async (req, res) => { const receipt = await Receipt.findById(req.params.id); res.json(receipt); })`. The team suggests using long, random UUIDs instead of sequential integers to fix this. What is the correct remediation? | pass→fail | 24,371 | 14,506 | -40% | 1 | 1 | 0% | 1,890 | 1,240 | -34% | 0 | 0 | — |
▸case-10 Audit this Python code: `os.system('ping -c 4 ' + user_ip)`. The developer proposes using a regex to ensure the input only contains numbers and dots. Provide the architectural remediation. | pass→pass | 21,043 | 13,635 | -35% | 1 | 1 | 0% | 2,457 | 2,570 | +5% | 0 | 0 | — |
▸case-11 Review this PHP user registration code: `$hash = md5($password);`. The team wants to upgrade to SHA-256 to make it secure. Detail the correct cryptographic remediation in a structured report. | fail→fail | 21,505 | 12,812 | -40% | 1 | 1 | 0% | 2,928 | 2,521 | -14% | 0 | 0 | — |
▸case-12 Generate a security report for a Spring Boot endpoint that redirects users based on a query parameter: `return "redirect:" + request.getParameter("url");`. The team suggests checking if the URL starts with 'http'. What is the secure remediation? | pass→pass | 15,858 | 15,662 | -1% | 1 | 1 | 0% | 1,630 | 3,084 | +89% | 0 | 0 | — |
▸case-13 Audit this Nginx configuration serving a web application over HTTPS. It currently lacks any custom security headers. The operations team suggests adding `X-Powered-By: Nginx` to clarify the stack. What specific headers should be added for security? | pass→pass | 13,427 | 11,548 | -14% | 1 | 1 | 0% | 2,730 | 1,811 | -34% | 0 | 0 | — |
▸case-14 Review an authentication API endpoint that processes login attempts without any request limits. The product manager suggests adding a CAPTCHA on every single login attempt. Provide the standard DevSecOps remediation. | fail→pass | 15,329 | 18,085 | +18% | 1 | 1 | 0% | 2,734 | 2,788 | +2% | 0 | 0 | — |
▸case-15 Provide a security assessment for a microservice validating JWTs where it accepts tokens with the 'alg' header set to 'none'. The developer suggests encrypting the JWT payload to fix this. What is the correct remediation? | pass→pass | 12,538 | 18,410 | +47% | 1 | 1 | 0% | 2,148 | 2,526 | +18% | 0 | 0 | — |
▸case-16 Audit this C code that checks if a file exists using `access()`, and then opens it using `fopen()` a few lines later. The developer suggests reducing the time between the two calls by removing intermediate logging. Detail the correct remediation. | fail→fail | 12,935 | 13,726 | +6% | 1 | 1 | 0% | 2,551 | 2,711 | +6% | 0 | 0 | — |
▸case-17 Generate a security report for a Ruby on Rails controller updating a user profile: `@user.update(params[:user])`. The team suggests adding a hidden form field to verify the update intent. What is the actual vulnerability and fix? | pass→pass | 12,493 | 10,114 | -19% | 1 | 1 | 0% | 1,909 | 1,847 | -3% | 0 | 0 | — |
▸case-18 Review a web application that does not restrict how it can be embedded in iframes. The front-end team proposes writing a JavaScript frame-busting script. Provide the modern, standard remediation. | pass→pass | 10,889 | 12,186 | +12% | 1 | 1 | 0% | 1,920 | 2,466 | +28% | 0 | 0 | — |
▸case-19 Design a DevSecOps pipeline integration for a new SAST tool in GitHub Actions. The engineering manager suggests running the tool asynchronously and emailing the results to the security team once a week. What is the standard integration practice? | pass→pass | 13,167 | 13,898 | +6% | 1 | 1 | 0% | 2,186 | 2,542 | +16% | 0 | 0 | — |
▸case-20 Map a newly discovered SQL Injection vulnerability in the payment processing module to the PCI-DSS v4.0 standard for the compliance audit report. The team suggests mapping it to physical security requirements. Provide the correct mapping. | pass→pass | 10,854 | 12,076 | +11% | 1 | 1 | 0% | 1,902 | 1,725 | -9% | 0 | 0 | — |
▸case-21 Audit this Node.js regex used to validate user input: `/^([a-zA-Z0-9]+\s?)*$/`. The developer suggests wrapping the regex execution in a try-catch block to handle errors. Detail the vulnerability and remediation. | fail→fail | 15,551 | 14,122 | -9% | 1 | 1 | 0% | 2,926 | 2,847 | -3% | 0 | 0 | — |
▸case-22 Review this Python snippet for a web application and provide a structured security audit report: `cursor.execute("SELECT * FROM users WHERE username = %s", (user_input,))`. The team is worried about SQL injection and suggests using string concatenation instead. Provide a structured review. | pass→pass | 11,693 | 23,171 | +98% | 1 | 1 | 0% | 2,179 | 2,374 | +9% | 0 | 0 | — |
▸case-23 Generate a security audit report for this React component: `<div>{props.userData}</div>`. A junior developer suggested writing a custom regex to strip out `<script>` tags to prevent XSS. Provide the industry-standard remediation. | pass→pass | 14,201 | 10,954 | -23% | 1 | 1 | 0% | 2,468 | 2,195 | -11% | 0 | 0 | — |
▸case-24 Review this PHP user registration code: `$hash = password_hash($password, PASSWORD_ARGON2ID);`. The team wants to upgrade to MD5 to make it secure. Detail the correct cryptographic remediation in a structured report. | pass→pass | 15,440 | 16,988 | +10% | 1 | 1 | 0% | 2,476 | 2,541 | +3% | 0 | 0 | — |