Four-scanner A/B/C/D evaluation · OWASP Juice Shop

AudnvsCodexvsAikidovsMythos

Executive verdict

Four scanners on the same Juice Shop source — four different lenses. Together they filed 235 findings, but they cluster, and where they independently converge is the signal.

Audn live red-team (103, 18 reproduced live). Codex commit-diff review (20, patched). Aikido SAST + SCA + secrets (36, ~52s). Mythos Claude-native whole-repo deep static (76) — the broadest static reasoner, and it reads code + tests + challenge definitions to separate intended from unintended.

All four independently agree on 4 areas — SSRF, code injection/RCE, JWT signature-not-verified, and unpinned CI supply chain — the closest thing to "certainly real" here. The new story: Mythos closes the availability blind spot the first three barely touched — 10 DoS / resource-exhaustion findings, 4 uncaught-exception process crashes, and ReDoS — plus the deepest IDOR set (12), each mapped to its intended challenge.

Each still owns an irreducible lane: Audn = live proof + business-logic/crypto; Aikido = SCA dependency CVEs + secrets breadth; Codex = changeset regressions + fix patches; Mythos = DoS/robustness depth + the broadest, most reachability-aware static reasoning. Run them as layers — fast static baseline, PR gate, deep pre-merge review, and a live merge-gate pentest. Remaining blind spots shrink to three: live infra/edge posture (unresolved), complete SCA/SBOM, and live exploit confirmation of the ~215 static findings.

103
Audn
18 live · red-team
20
Codex
diff-scoped · patches
36
Aikido
+3 dep CVEs · ~52s
76
Mythos
10 DoS · deepest static

Four tools, four jobs

Same target (ozguratwayve/juice). The severity mixes and "scanner DNA" chips show the split: Audn ranges across a live-confirmed critical tier, Codex a tight introduced-issue set, Aikido a static baseline heavy on secrets, and Mythos a broad deep-static sweep weighted toward High-severity logic, DoS and robustness.

Audn

SAST fused with a live red-team run against the deployed target. CWE, file:line, CVSS, confidence tiers, attack paths.
Severity103
18245254
SAST + live DAST2h 28m

Codex

Commit-diff code review of one changeset. Validation rubric + evidence + a generated patch per finding.
Severity20
8723
diff-aware SAST+ patches

Aikido

Commercial platform: SAST + SCA + secrets + CI/IaC in one pass. Continuous per-repo, "fix time" estimates.
Severity36
313812
SAST+SCA+secrets+CI~52s

Mythos

Claude-native whole-repo deep static review. Reads code, tests & challenge defs; precise reachability + intended-vs-unintended.
Severity76
745213
deep static reasoningwhole repo
CriticalHighMediumLowInfo

Only Audn grades its own certainty — the other three are static

Audn separates "facts about the running system" from "patterns in the source": 16 confirmed (static+live) + 2 observed live, vs 63 static-only leads. Codex, Aikido and Mythos are all fully static — every one of their 132 findings sits, in Audn's terms, at the unverified tier (however precise Mythos's reachability reasoning is).

Audn findings by confidence tier
Confirmed16
Observed live2
Probed, no verdict18
Static lead63
Likely false positive4

A/B/C/D — pros & cons

Pick by the job. Fast static baseline → Aikido. PR diff gate → Codex. Deep whole-repo review → Mythos. Prove exploitability → Audn.

Audn

Pros
  • Live reproduction (18) — only exploit proof here.
  • Business-logic & crypto depth.
  • Confidence tiers.
  • Attack-path chains + CVSS.
Cons
  • Mostly unconfirmed (63 leads).
  • Slow (2h 28m), needs live target.
  • No SCA; no patches.

Codex

Pros
  • Catches introduced regressions.
  • Diff-aware — PR gate.
  • Ships a patch per finding.
  • Separates intentional vs real.
Cons
  • Narrow (20) — one changeset.
  • No live proof.
  • No SCA / secrets sweep.

Aikido

Pros
  • Only SCA — 3 dependency CVEs.
  • Deep secrets (incl. tests).
  • Fastest (~52s).
  • Multi-engine, continuous.
Cons
  • Static only.
  • Noisy — test-fixture "secrets".
  • No business-logic / IDOR; incomplete SCA (no lockfile).

Mythos

Pros
  • Broadest static (76) + deepest reasoning.
  • Owns DoS / robustness (10 + 4).
  • Reachability + challenge-aware — precise, low-noise.
  • Whole-repo (not diff-scoped).
Cons
  • No live proof (static).
  • No SCA / dependency CVEs.
  • No secrets-in-tests sweep; heavier than a diff scan.

Methodology, side by side

DimensionAudnCodexAikidoMythos
Core methodSAST + live red-teamDiff reviewSAST+SCA+secrets+CIDeep whole-repo static
ScopeWhole app, deployedOne changesetWhole repoWhole repo + tests + challenge defs
Findings103203676
Live confirmation18 + tiersNoneNoneNone (static)
Dependency CVEs (SCA)NoNoYes (3)No
DoS / robustnessLight (3+1)1NoneHeavy (10+4)
RemediationProse + pathsPatchFix-time + guidancePrecise fix criteria
Intentional vs unintendedNoYesNoYes (per challenge)
Speed2h 28mLight~52sMedium
Sweet spotPentestPR gateContinuous baselineDeep pre-merge review

Gap analysis — four ways

Overlap is mapped at the issue-area level (the taxonomies differ). Each tool owns a distinct lane; the areas all four independently reach are the highest-confidence issues in the whole set.

What each tool uniquely brings

Audn

Live exploit proof

The only scanner that ran against a deployed target and reproduced 18 findings live. Owns the business-logic / crypto lane too — weak password recovery, unbounded coupons, wallet overspend — and grades its own certainty (confirmed vs lead).

  • Only live confirmation (18)
  • Business-logic & crypto depth
  • Confidence tiers

Codex

Changeset lens + patches

Diff-scoped review that flags what a commit introduced — regressions, a privacy leak (Google Fonts), a Windows i18n bug, Junie-skill SSRF — and ships a patch per finding. The only "what did this PR break" view.

  • Introduced vs pre-existing
  • Privacy / cross-platform regressions
  • Fix diffs

Aikido

SCA + secrets + speed

The only tool that runs SCA — 3 dependency CVEs (jsonwebtoken, express-jwt, sanitize-html) — plus a broad secrets sweep across 40+ files incl. tests, in ~52 seconds.

  • Dependency CVEs (SCA) — unique
  • Secrets incl. test fixtures
  • Fastest (52s)

Mythos

Deepest static — DoS & robustness

Claude-native whole-repo review, 76 findings — the broadest static reasoning. Uniquely owns the availability lane: 10 DoS / resource-exhaustion, 4 uncaught-exception process crashes, ReDoS — plus the deepest IDOR set (12), each mapped to the intended challenge.

  • DoS / resource-exhaustion (10)
  • Uncaught-exception crashes (4)
  • Deepest IDOR + challenge-aware

① Where all four independently agree — highest confidence

A live red-team, a diff reviewer, a commercial SAST/SCA platform, and a Claude-native deep static scanner all landing on the same class = as close to "definitely real" as it gets.

JWT signature is not verified / forgeable

Hard-coded key + algorithm confusion in lib/insecurity.ts — every tool reaches it (Audn #22/#35, Codex #3/#4, Aikido, Mythos).

Unpinned 3rd-party GitHub Actions w/ write token

image_actions.yml / ci.yml — flagged by all four (Audn #54, Codex #1/#2, Aikido, Mythos).

Code injection / RCE

Server-side eval / template injection in userProfile.ts, dataErasure.ts, b2bOrder.ts — all four reach the class (Mythos deepest, 5).

SSRF

Server-side request forgery via profile-image URL / chat parts — reached by all four.

② Mythos's distinctive contribution — the availability lane no one else worked

14 of Mythos's findings are DoS / resource-exhaustion or process-crashing uncaught exceptions — a class Audn touched lightly (exploit-focused), Codex once, and Aikido not at all. Hover a chip for location + CWE.

10
DoS / resource-exhaustion — the availability lane no one else worked
Client-chosen multipart Content-Type becomes a permanent PromethUnauthenticated repeat-notification appends to the unbounded gloCode-fix cache permanently stores an entry for every arbitrary rPhoto-wall upload persists unbounded, unvalidated files into theBackend i18n catalog learns attacker-supplied phrases: unboundedQuadratic regex on unauthenticated socket.io 'verifySvgInjectionQuadratic regex on unauthenticated XML upload output stalls the Per-request full scan and bigram similarity over all complaints Unauthenticated wallet-address submissions permanently grow an iUnvalidated feedback rating drives Array(rating).fill() on the A
4
Uncaught exceptions that crash the process
Un-awaited quantityCheck on PUT /api/BasketItems/:id rejects unhFailed avatar download at startup causes unhandled rejection thaPromotion page crashes process when subtitles configured as URL Empty layout render dereferences null error in hbs completion ca

③ The irreducible lanes — areas only one tool reached

Even with four scanners, these classes came from a single tool — proof they're complementary, not redundant.

Only Audn

  • Weak password recovery — seeded security answers.
  • Weak credential hashing — MD5.
  • Business logic — client-clock coupons, unbounded discounts.
  • Cleartext transmission — plain-HTTP config.
  • Insufficient verification — anti-cheat, login-IP spoof.
  • + live confirmation of 18 exploits.

Only Aikido

  • Dependency CVEs (SCA) — jsonwebtoken, express-jwt, sanitize-html.
  • Secrets in test fixtures — 40+ files.
Codex only
  • Introduced privacy leak (Google Fonts), Windows i18n bug, Junie-skill SSRF, test-coverage regressions — the diff-scoped set.

④ Unknown unknowns — updated for four tools

Two of the earlier blind spots are now covered — dependency CVEs (Aikido) and DoS/robustness (Mythos). What still isn't covered by any of the four:

✓
Dependency / component CVEs Covered — Aikido SCA

Aikido's 3 CVEs; still partial (missing lockfile → add one for full transitive SCA).

✓
DoS / availability & robustness Covered — Mythos

Mythos's 10 resource-exhaustion + 4 uncaught-exception findings close the class the other three skipped.

1
Live infrastructure / edge posture unresolved

All of Codex, Aikido and Mythos are static; Audn ran live but its transport/header/container items were never reached (#61) or probed with no verdict (#21). The real TLS, the HTTP security headers the edge returns, container hardening — still unresolved, not measured. One curl -I closes most of it.

2
Live exploit confirmation of the static majority confidence

Audn confirmed 18 live; the other ~215 findings (Codex 20 + Aikido 36 + Mythos 76 + Audn's 85 unconfirmed) are static. Mythos reasons hard about reachability, but nothing except Audn proved it against a running instance.

3
Complete SCA / SBOM supply chain

Only Aikido does SCA and it flagged a missing lockfile; no full transitive graph, license posture, or signed SBOM across the four.

Coverage matrix — by vulnerability class

Where each tool put its attention. ●●● strong (8+), ●● moderate (3–7), ● light (1–2), — none. Green rows = all four reached the class; the left rule marks a class only one tool reached. The clearest single view of the four-way spread.

Vulnerability classAudnCodexAikidoMythos
SQL Injection●2——●1●2
NoSQL Injection●●3——●1——
XSS●●6——●●3●●●8
XXE●1————●1
SSRF●1●2●1●1
Path Traversal●●6——●2●●3
Code Injection / RCE●2●1●2●●5
Insecure Deserialization————●1●1
Broken Access Control / IDOR●●●16●2——●●●12
JWT / Token Auth●●3●2●1●2
Broken Authentication●●3————●●3
Auth Rate-Limiting●●3————●2
Weak Password Recovery●1——————
Weak Credentials/Hashing●2——————
Hardcoded Secrets/Creds●●●11——●●●17●1
Sensitive Data Exposure●●●13●2——●●6
Open Redirect●1——●1●1
CSRF●2————●2
Broken Anti-Automation●2————●1
Business Logic●2——————
Race Condition●2●2————
Improper Input Validation●●4●2——●●7
Cleartext Transmission●2——————
DoS / Resource Exhaustion●●3●1——●●●10
Robustness / Uncaught Exception●1————●●4
Supply Chain / CI-CD●●●8●●6●●3●●4
Dependency CVE (SCA)————●●3——
Insufficient Verification●●3——————

Counts are findings tagged to each class (Codex/Aikido/Mythos aggregated from their finding lists). Note Mythos's dominance in DoS/Resource-Exhaustion and Robustness, Aikido's sole Dependency-CVE row, and Audn's IDOR/Sensitive-Data depth.

All findings

Every finding from all four reports, filterable — 235 total, the working index behind the analysis.

Mythos — 76 findings

Severity
SevFindingCWELocationCategory
CriticalReset-password rate limiter keyed on client-chosen X-Forwarded-For/req.ip under trust proxy: unbounded brute force of …CWE-307server.ts:340Authentication brute force
CriticalUnauthenticated POST /api/SecurityAnswers binds caller-chosen UserId: plant recovery answer, reset any answerless acco…CWE-639server.ts:394Authentication bypass
CriticalUnauthenticated /rest/track-order $where injection: 60-char cap does not stop process kill or in-process code executio…CWE-95routes/trackOrder.ts:13Code injection
CriticalUnauthenticated in-process JavaScript execution via MarsDB $where in product reviews lookupCWE-95routes/showProductReviews.ts:31Code injection
CriticalUnauthenticated RCE via js-yaml 3.x !!js/function + JSON.stringify toJSON in complaint YAML uploadCWE-502routes/fileUpload.ts:104Insecure deserialization
CriticaldenyAll() guard is a JWT verifier that accepts alg=none, opening every forbidden finale verbCWE-347lib/insecurity.ts:52Improper signature verification
CriticalLogin SQL injection via interpolated email: password-less login as any account and UNION read of the whole DB (intende…CWE-89routes/login.ts:34SQL injection
High2FA TOTP brute force: verify limiter keyed on spoofable X-Forwarded-For-derived req.ipCWE-307server.ts:458Authentication brute force
HighUnauthenticated /api/Recycles/:id JSON-parsed id dumps every user's recycle requests; POST binds foreign UserIdCWE-862routes/recycles.ts:11Missing authorization
HighUnauthenticated PUT /api/Hints/:id lets anyone rewrite hint text and re-parent hints, not just unlock themCWE-915server.ts:375Mass assignment
HighPUT /api/Products/:id has no guard: anonymous tampering of every product's name, price, image and description (documen…CWE-306server.ts:368Missing authentication
HighForged continue code marks every challenge solved and broadcasts all CTF flags to any socket.io client without solving…CWE-345routes/restoreProgress.ts:16Authentication bypass
HighUsername evaluated with eval() on GET /profile: server-side JavaScript/command execution (documented sstiChallenge / u…CWE-95routes/userProfile.ts:54Code injection
HighUploaded image files are compiled as Handlebars layouts: attacker-authored template executionCWE-1336routes/dataErasure.ts:103Server-side template injection
HighUsername spliced into Pug template source yields RCE even when SSTi challenge is disabledCWE-1336routes/userProfile.ts:62Server-side template injection
HighClient-chosen multipart Content-Type becomes a permanent Prometheus label: unbounded series growthCWE-770routes/metrics.ts:73Resource exhaustion
HighUnauthenticated repeat-notification appends to the unbounded global notification queue on every call; the whole queue …CWE-770lib/challengeUtils.ts:71Resource exhaustion
HighCode-fix cache permanently stores an entry for every arbitrary request-supplied key: unbounded heap growth from unauth…CWE-770routes/vulnCodeFixes.ts:18Resource exhaustion
HighPhoto-wall upload persists unbounded, unvalidated files into the served directory for any network client, written befo…CWE-770server.ts:698Resource exhaustion
HighBackend i18n catalog learns attacker-supplied phrases: unbounded in-memory and on-disk growth with synchronous full re…CWE-770server.ts:298Resource exhaustion
HighQuadratic regex on unauthenticated socket.io 'verifySvgInjectionChallenge' payload stalls the event loopCWE-1333lib/startup/registerWebsocketEvents.ts:45ReDoS
HighQuadratic regex on unauthenticated XML upload output stalls the single-process serverCWE-1333lib/utils.ts:220ReDoS
HighPer-request full scan and bigram similarity over all complaints enables stored CPU exhaustionCWE-400routes/verify.ts:371Algorithmic complexity DoS
HighUnauthenticated wallet-address submissions permanently grow an in-memory Set without boundCWE-770routes/web3Wallet.ts:15Resource exhaustion
HighHard-coded valid admin test-account credentials shipped in the login component bundle (documented exposedCredentialsCh…CWE-798frontend/src/app/login/login.component.ts:61Hard-coded credentials
HighStartup snippet scan parses the SQLite database file as source: stale user text with a snippet marker aborts every boo…CWE-20lib/codingChallenges.ts:5Improper Input Validation
HighUnauthenticated socket.io event with non-string payload throws uncaught TypeError and kills the server processCWE-1287lib/startup/registerWebsocketEvents.ts:40Improper Input Validation
HighBackslash path traversal in /ftp, /ftp/quarantine, /encryptionkeys and /support/logs file servers escapes the served d…CWE-22routes/keyServer.ts:11Path traversal
HighZip-slip in unauthenticated complaint upload overwrites per-request-compiled Pug templates: RCECWE-23routes/fileUpload.ts:27Path traversal
HighUn-awaited quantityCheck on PUT /api/BasketItems/:id rejects unhandled: authenticated user kills the processCWE-248routes/basketItems.ts:65Uncaught exception
HighFailed avatar download at startup causes unhandled rejection that terminates the serverCWE-248lib/startup/customizeApplication.ts:44Uncaught exception
HighPromotion page crashes process when subtitles configured as URL (startup/consumer filename mismatch)CWE-248routes/videoHandler.ts:80Uncaught exception
HighProduct search SQL injection lets one anonymous GET hang the shared SQLite connection and libuv threadpool indefinitel…CWE-89routes/search.ts:21SQL injection
HighUnauthenticated SSRF via URL-typed image/file parts in chatbot messagesCWE-918routes/chat.ts:191Server-Side Request Forgery
HighPublic application-configuration endpoint discloses seeded security answers and OSINT challenge answersCWE-201routes/appConfiguration.ts:9Information disclosure
HighAnonymous serve-index listings and downloads of /ftp, /support/logs, /encryptionkeys, /.well-known (documented challen…CWE-548server.ts:269Directory listing exposure
HighCustomer order confirmation PDFs (unmasked email, purchases) written into the publicly listed /ftp directory and reada…CWE-538routes/order.ts:40Sensitive data exposure
HighPublic product-review listing discloses the email addresses of every user who liked a reviewCWE-359routes/showProductReviews.ts:36Information disclosure
HighPassword reset response returns the victim's full user row (totpSecret, password hash), turning a guessed security ans…CWE-201routes/resetPassword.ts:42Information exposure
HighPublic GET /rest/memories serialises each memory owner's full User row (MD5 password hash, totpSecret, deluxeToken, la…CWE-200routes/memory.ts:22Information disclosure
HighMutable third-party action refs run with write-scoped GITHUB_TOKEN on release-branch pushesCWE-829.github/workflows/image_actions.yml:29Supply chain
HighUnpinned lint toolchain runs with persisted write token; its output is auto-committed to release branchesCWE-494.github/workflows/lint-fixer.yml:3Supply chain compromise
HighE2E spec makes the CI server process download and execute an unpinned, unverified binary from a maintainer's personal …CWE-494test/cypress/e2e/profile.spec.ts:50Unverified code download
HighForgeable z85 coupons with unbounded discount (forgedCouponChallenge; >100% overlaps negativeOrderChallenge)CWE-649lib/insecurity.ts:97Missing integrity check
HighStored XSS: data export JSON written unescaped via document.write into same-origin windowCWE-79frontend/src/app/data-export/data-export.component.ts:71Cross-site scripting
HighScore board renders challenge records as trusted HTML; anonymous challenge rewrite yields stored XSS on every visitorCWE-79frontend/src/app/score-board/score-board.component.ts:82Cross-site scripting
HighStored XSS: product descriptions marked trusted HTML and rendered via innerHTMLCWE-79frontend/src/app/search-result/search-result.component.ts:108Cross-site scripting
HighReflected DOM XSS via order tracking id (reflectedXssChallenge): server echoes unmatched id, client marks it trusted H…CWE-79frontend/src/app/track-result/track-result.component.ts:45Cross-site scripting
HighStored XSS against administrators: user email persisted unsanitised (persistedXssUserChallenge enabled) and rendered a…CWE-79models/user.ts:59Cross-site scripting
HighReflected DOM XSS: search query parameter rendered via bypassSecurityTrustHtmlCWE-79frontend/src/app/search-result/search-result.component.ts:136Cross-site scripting
HighStored XSS via SVG profile image fetched from attacker URL and served on the app originCWE-79routes/profileImageUrlUpload.ts:28Cross-site scripting
HighSafety Mode does not disable XXE/YAML-bomb parsing: gate checks a never-disabled challengeCWE-611routes/fileUpload.ts:73XML external entity injection
MediumPUT-only Address/BasketItem guards leave PATCH unguarded if finale-rest binds update to PATCHCWE-862server.ts:450Missing authorization
MediumDeluxe upgrade granted without payment when paymentMode is neither 'wallet' nor 'card' (documented freeDeluxeChallenge…CWE-841routes/deluxe.ts:24Privilege escalation
MediumGET /rest/basket/:id returns any user's basket to any authenticated caller (documented basketAccessChallenge)CWE-639routes/basket.ts:18Insecure direct object reference
MediumOrders keyed by vowel-masked email leak look-alike users' order history (dataExportChallenge)CWE-639routes/orderHistory.ts:13Insecure direct object reference
MediumBasketItem API: list and by-id GET/PUT/DELETE act on any user's basket items without basket-ownership checkCWE-639server.ts:358Insecure direct object reference
MediumGET /api/Users, /api/Users/:id and /rest/user/authentication-details expose all users' records to any authenticated ac…CWE-862server.ts:362Missing authorization
MediumGET /api/Complaints returns every user's complaint text to any authenticated account; POST /api/Complaints stores a ca…CWE-862server.ts:380Missing authorization
MediumPUT /api/Addresss/:id updates any user's address; appendUserId re-owns it to the callerCWE-639server.ts:450Insecure direct object reference
MediumCheckout and coupon routes act on any basket id without ownership checkCWE-639routes/order.ts:34Insecure direct object reference
Mediumfinale search on GET /api/Users?q= matches excluded password and totpSecret columns (oracle for hash/2FA-secret extrac…CWE-203server.ts:483Observable discrepancy
MediumPassword change skips current-password verification when `current` is omitted (changePasswordBenderChallenge); passwor…CWE-620routes/changePassword.ts:39Unverified password change
MediumGoogle OAuth implicit-flow callback accepts any access_token, enabling login CSRF into attacker accountCWE-352frontend/src/app/oauth/oauth.component.ts:27Cross-site request forgery
MediumUnvalidated feedback rating drives Array(rating).fill() on the Administration page, hanging or breaking itCWE-770frontend/src/app/administration/administration.component.ts:133Uncontrolled resource consumption
MediumNegative basket quantities pass the stock/limit checks and a negative order total credits the buyer's wallet and infla…CWE-1284routes/basketItems.ts:92Improper Input Validation
MediumPOST /api/BasketItems: ownership check reads the first BasketId, the write reads the last — duplicate-key parser diffe…CWE-436routes/basketItems.ts:21Interpretation conflict
MediumtestDecal query parameter controls SVG image href on deluxe page (svgInjectionChallenge)CWE-99frontend/src/app/deluxe-user/deluxe-user.component.ts:57Resource injection
MediumStartup asset download persists unvalidated remote response bytes into the served static treeCWE-829lib/utils.ts:114Untrusted remote content inclusion
MediumSecurity answers stored as HMAC-SHA256 under a hard-coded public key: offline recovery of every user's recovery secretCWE-321lib/insecurity.ts:42Hard-coded cryptographic key
MediumRedirect allowlist uses substring match: open redirect to any URL (intended challenges redirectChallenge / redirectCry…CWE-601lib/insecurity.ts:133Open redirect
MediumEmpty layout render dereferences null error in hbs completion callback; with the view template cached the TypeError is…CWE-476routes/dataErasure.ts:110NULL pointer dereference
MediumProduct image field concatenated into CSS background-image url() lets anonymous product tampering load an external bea…CWE-79frontend/src/app/product/product.component.html:34CSS injection
LowPOST /profile changes the username on cookie-only authentication with no CSRF defence (documented csrfChallenge)CWE-352routes/updateUserProfile.ts:17Cross-site request forgery
LowAccounting inventory table dereferences missing Quantity row; any customer-created product breaks the pageCWE-476frontend/src/app/accounting/accounting.component.html:94Improper Input Validation
LowUnvalidated language cookie steers translation loader to attacker-uploaded JSON via path traversalCWE-22frontend/src/app/navbar/navbar.component.ts:203Path traversal

Audn — 103 findings

Severity
#SevFindingCWELocationConfidenceOverlap
#1CriticalSensitive information written to log file LIVECWE-532server.ts:280ConfirmedAudn only
#2CriticalUnthrottled password-reset (spoofable X-Forwarded-For) LIVECWE-307server.ts:340ConfirmedAudn only
#3CriticalOAuth derives predictable password from email LIVECWE-521frontend/src/app/oauth/oauth.component.ts:27ConfirmedAudn only
#4CriticalWallet recovery mnemonic committed in plaintext LIVECWE-321data/static/users.yml:259ConfirmedAudn only
#5CriticalHard-coded admin credentials in seed data LIVECWE-798data/static/users.yml:167ConfirmedAudn only
#6CriticalHard-coded security-question answers LIVECWE-798config/7ms.yml:143ConfirmedAudn only
#7CriticalWeak password recovery via seeded answers LIVECWE-640routes/resetPassword.ts:18ConfirmedAudn only
#8CriticalHard-coded credentials in login handler LIVECWE-798routes/login.ts:59ConfirmedAudn only
#9HighSQL injection in product search LIVECWE-89routes/search.ts:21ConfirmedAudn only
#10HighNoSQL injection in track-order LIVECWE-943routes/trackOrder.ts:15ConfirmedAudn only
#11HighNoSQL injection in product reviews LIVECWE-943routes/showProductReviews.ts:31ConfirmedAudn only
#12HighWeak (MD5) password hashing LIVECWE-916models/user.ts:73ConfirmedAudn only
#13HighStored XSS in product LIVECWE-79models/product.ts:42ConfirmedAudn only
#14HighSensitive info exposure via memories LIVECWE-200routes/memory.ts:22ConfirmedAudn only
#15HighUnthrottled 2FA verification LIVECWE-307routes/2fa.ts:16ConfirmedAudn only
#16HighChallenge flag exposed in notification LIVECWE-200lib/challengeUtils.ts:52ConfirmedAudn only
#17CriticalSpoofable X-Forwarded-For bypasses reset rate limit LIVEObservedAudn only
#18CriticalPublic access logs contain cleartext change-password URLs LIVEObservedAudn only
#19CriticalZIP upload overwrites arbitrary application files CWE-22routes/fileUpload.ts:27ProbedAudn only
#20CriticalSearch query causes DOM-based XSS CWE-79frontend/src/app/search-result/search-result.component.ts:135ProbedAudn only
#21CriticalMutable base images enter production builds CWE-829Dockerfile:1ProbedAudn+Codex
#22CriticalHard-coded JWT private key enables token forgery CWE-321lib/insecurity.ts:20ProbedAudn+Codex
#23CriticalRelease tag enables cross-repo command injection CWE-78.github/workflows/update-news-www.yml:18ProbedAudn+Codex
#24CriticalTracking ID enables reflected XSS CWE-79frontend/src/app/track-result/track-result.component.ts:45ProbedAudn only
#25CriticalBuild argument injects arbitrary npm packages CWE-88Dockerfile:18ProbedAudn+Codex
#26HighAnonymous XML upload discloses local files (XXE) CWE-611server.ts:307ProbedAudn only
#27HighProfile image URL enables SSRF CWE-918server.ts:307ProbedAudn only
#28HighUnbounded upload can exhaust server disk CWE-400server.ts:698ProbedAudn only
#29HighBackslashes bypass quarantine path validation CWE-22routes/quarantineServer.ts:10ProbedAudn only
#30HighOrder data enables remote code execution CWE-94routes/b2bOrder.ts:19ProbedAudn only
#31HighStored username enables server-side code execution CWE-95routes/userProfile.ts:54ProbedAudn only
#32HighRemote installer executes without integrity verification CWE-494.github/workflows/ci.yml:357ProbedAudn+Codex
#33HighRemote SVG upload enables stored XSS CWE-79server.ts:310ProbedAudn only
#34HighLockless installs execute mutable dependency code CWE-829.npmrc:1ProbedAudn+Codex
#35HighJWT verification trusts attacker-selected algorithm CWE-347lib/insecurity.ts:52ProbedAudn+Codex
#36HighRelease tag injects commands into legacy website update CWE-78.github/workflows/update-news-www-legacy.yml:18ProbedAudn+Codex
#37CriticalLogin query permits authentication bypass CWE-89routes/login.ts:32Static leadAudn only
#38HighNull-suffix bypass enables Windows file traversal CWE-22routes/fileServer.ts:16Static leadAudn only
#39HighPassword change skips current-password check CWE-620routes/changePassword.ts:39Static leadAudn only
#40HighEndpoint exposes complete runtime configuration CWE-200routes/appConfiguration.ts:10Static leadAudn only
#41HighRepository code executes with CI secrets CWE-200.github/workflows/ci.yml:229Static leadAudn only
#42HighSecurity-answer bypass permits unverified erasure CWE-620routes/dataErasure.ts:74Static leadAudn only
#43MediumProduction error handler exposes stack traces CWE-209server.ts:314Static leadAudn only
#44MediumMetrics endpoint exposed without authentication CWE-200server.ts:725Static leadAudn only
#45MediumAnonymous FTP directory listing exposes hidden files CWE-548server.ts:267Static leadAudn only
#46MediumAnonymous users can modify products CWE-862server.ts:368Static leadAudn only
#47MediumYAML aliases block the Node.js event loop CWE-400routes/fileUpload.ts:101Static leadAudn only
#48MediumSubstring allowlist permits arbitrary redirects CWE-601routes/redirect.ts:13Static leadAudn only
#49MediumUnbounded image download exhausts storage CWE-400routes/profileImageUrlUpload.ts:24Static leadAudn only
#50MediumUsers can edit reviews owned by others CWE-639routes/updateProductReviews.ts:16Static leadAudn only
#51MediumNoSQL selector updates every product review CWE-943routes/updateProductReviews.ts:17Static leadAudn only
#52MediumOrdinary users can enumerate all user profiles CWE-862routes/authenticatedUsers.ts:10Static leadAudn only
#53MediumArbitrary field selection exposes credential material CWE-200routes/currentUser.ts:20Static leadAudn only
#54MediumMutable actions receive repo write capability CWE-829.github/workflows/image_actions.yml:29Static leadAudn+Codex
#55MediumUnversioned Playwright install can overwrite master CWE-829.github/workflows/frontend-bundle-analysis.yml:39Static leadAudn only
#56MediumUnvalidated seed data can create administrators CWE-20data/staticData.ts:55Static leadAudn only
#57MediumApplication name injects executable HTML CWE-79lib/startup/customizeApplication.ts:83Static leadAudn only
#58MediumAnonymous callers can forge product reviews CWE-862routes/createProductReviews.ts:14Static leadAudn only
#59MediumUnverified JWT controls chatbot order identity CWE-347routes/chat.ts:42Static leadAudn+Codex
#60MediumCoupon policy enforced only by the LLM CWE-862routes/chat.ts:176Static leadAudn+Codex
#61MediumDefault deployment exposes credentials over plain HTTP CWE-319server.ts:130Static leadAudn only
#62MediumBender account password exposed client-side CWE-798frontend/src/hacking-instructor/challenges/loginBender.ts:75Static leadAudn only
#63MediumJim account password exposed client-side CWE-798frontend/src/hacking-instructor/challenges/loginJim.ts:64Static leadAudn only
#64MediumCAPTCHA response discloses its answer CWE-200routes/captcha.ts:22Static leadAudn only
#65MediumSolved CAPTCHAs remain valid for unlimited reuse CWE-294routes/captcha.ts:35Static leadAudn only
#66MediumFailed requests satisfy global anti-cheat checks CWE-345lib/antiCheat.ts:51Static leadAudn only
#67MediumCommitted CTF key permits flag forgery CWE-321ctf.key:1Static leadAudn only
#68MediumProduct link uses cleartext HTTP CWE-319config/addo.yml:57Static leadAudn only
#69MediumClient clock controls campaign coupon validity CWE-602frontend/src/app/payment/payment.component.ts:152Static leadAudn only
#70MediumFeedback accepts ratings outside valid range CWE-20models/feedback.ts:57Static leadAudn only
#71MediumBasket IDOR exposes other users carts CWE-639routes/basket.ts:18Static leadAudn only
#72MediumDuplicate BasketId bypasses ownership check CWE-639routes/basketItems.ts:21Static leadAudn only
#73MediumCoupon update lacks basket ownership check CWE-639routes/coupon.ts:11Static leadAudn only
#74MediumUser-controlled layout enables local file disclosure CWE-22routes/dataErasure.ts:103Static leadAudn only
#75MediumCAPTCHA answer disclosed in API response CWE-200routes/imageCaptcha.ts:24Static leadAudn only
#76MediumMissing CAPTCHA record bypasses verification CWE-693routes/imageCaptcha.ts:42Static leadAudn only
#77MediumWallet debit permits concurrent overspending CWE-362routes/order.ts:148Static leadAudn only
#78MediumCheckout lacks basket ownership validation CWE-639routes/order.ts:34Static leadAudn only
#79MediumArray ID exposes multiple recycle records CWE-639routes/recycles.ts:11Static leadAudn only
#80MediumPremium content served without authorization CWE-862routes/premiumReward.ts:12Static leadAudn only
#81MediumResponse discrepancy enables account enumeration CWE-204routes/securityQuestion.ts:12Static leadAudn only
#82MediumArbitrary wallet balance top-ups CWE-20routes/wallet.ts:23Static leadAudn only
#83MediumClient header spoofs stored login IP CWE-345routes/saveLoginIp.ts:18Static leadAudn only
#84MediumMasked-email collisions expose other users orders CWE-639routes/orderHistory.ts:13Static leadAudn only
#85MediumAuthentication token contains the TOTP seed CWE-200routes/2fa.ts:26Static leadAudn only
#86MediumUnverified issue references defeat spam enforcement CWE-840.github/workflows/pr-compliance.yml:275Static leadAudn only
#87MediumAny commenter can rebase pull requests CWE-862.github/workflows/rebase.yml:3Static leadAudn only
#88MediumLossy email masking breaks order ownership CWE-187routes/chat.ts:158Static leadAudn+Codex
#89MediumNew commits bypass completed compliance decisions CWE-367.github/workflows/pr-compliance.yml:3Static leadAudn only
#90MediumJWT algorithm confusion accepts forged tokens CWE-347routes/verify.ts:111Static leadAudn+Codex
#91MediumAnonymous users can access arbitrary orders CWE-639routes/trackOrder.ts:12Static leadAudn only
#92MediumOAuth flow omits state validation CWE-352frontend/src/app/login/login.component.ts:147Static leadAudn only
#93MediumUnanchored coupon validation accepts unbounded discounts CWE-20lib/insecurity.ts:102Static leadAudn only
#94MediumGenerated users share a hard-coded password CWE-798data/datacreator.ts:310Static leadAudn only
#95LowConcurrent requests inflate review likes CWE-362routes/likeProductReviews.ts:25Static leadAudn only
#96LowPublic wallet address accepted as ownership proof CWE-345routes/nftMint.ts:41Static leadAudn+Codex
#97LowProfile update lacks CSRF enforcement CWE-352routes/updateUserProfile.ts:16Static leadAudn only
#98LowWallet ownership is never verified CWE-862routes/web3Wallet.ts:14Static leadAudn+Codex
#99LowTOTP secrets stored unencrypted CWE-312routes/2fa.ts:105Static leadAudn only
#100InfoActive user credentials embedded in client code CWE-798frontend/src/hacking-instructor/challenges/exposedCredentials.ts:51Likely FPAudn only
#101InfoFeedback XSS compromises administrator sessions CWE-79frontend/src/app/administration/administration.component.ts:86Likely FPAudn only
#102InfoBackslashes bypass log path validation CWE-22routes/logfileServer.ts:9Likely FPAudn only
#103InfoBackslashes bypass key-file path restriction CWE-22routes/keyServer.ts:10Likely FPAudn only

Aikido — 36 findings

Severity
Engine
#SevIssueEngineLocationOverlap
#1Criticaljsonwebtoken — attacker can abuse missing input validationDependencydependency (jsonwebtoken)Aikido only
#2CriticalRemote Code Execution via eval()-type functionsCodeuserProfile.tsAudn+Aikido
#3CriticalUnsafe YAML load can lead to RCECodevulnCodeSnippet.ts, vulnCodeFixes.tsAikido only
#4HighNoSQL injection attack possibleCodedeluxe.ts, wallet.ts +19Audn+Aikido
#5HighJWT signature is not verifiedCodeinsecurity.ts, authenticatedUsers.tsA+C+K
#6HighPath traversal via Express sendFile()CodefileServer.tsAudn+Aikido
#7HighSQL injection via string concatenationCodedbSchemaChallenge_1.ts, unionSqlInjectionChallenge_1.ts +3Audn+Aikido
#8HighOpen redirect usable in social engineeringCoderedirect.tsAudn+Aikido
#9HighServer-Side Template Injection via express.render()CodedataErasure.tsAudn+Aikido
#10Highexpress-jwt — attacker can abuse improper authorizationDependencydependency (express-jwt)Aikido only
#11High6 exposed secretsSecretusers.ymlAudn+Aikido
#12High4 exposed secretsSecretlogin.ts, login.jsAudn+Aikido
#13Highdocument.write() methods can lead to XSSCodeindex.tsAikido only
#14HighXSS via window.location.hrefCodeorder-history.component.tsAikido only
#15HighFile inclusion via reading fileCodevalidatePreconditions.ts, rsnUtil.ts +9Aikido only
#16High3rd party GitHub Actions should be pinnedCI/IaCimage_actions.yml, ci.ymlA+C+K
#17Mediumsanitize-html — XSS attack possibleDependencydependency (sanitize-html)Aikido only
#18Medium1 exposed secretSecret.travis.ymlAikido only
#19Medium1 exposed secretSecretserver.jsAikido only
#20Medium1 exposed secretSecretusers.jsonAikido only
#21Medium33 exposed secretsSecretdatacreator.js, chat.test.ts +21Aikido only
#22MediumHTTP request might enable SSRFCodeprofileImageUrlUpload.tsAudn+Aikido
#23MediumBinary pulled from remote without integrity checkCI/IaCci.ymlA+C+K
#24MediumXSS via bypassSecurityTrustUrlCodetrack-result.component.ts, search-result.component.ts +2Audn+Aikido
#25Lowactions/checkout persists Git credentialsCI/IaCci.yml, codeql-analysis.yml +11Aikido only
#26Low1 exposed secretSecretoauth.component.spec.tsAikido only
#27LowExposed JWTSecretlast-login-ip.component.spec.tsAikido only
#28LowExposed JWTSecretapp.guard.spec.tsAikido only
#29LowExposed JWTSecretverify.unit.test.ts +4Aikido only
#30Low6 exposed secretsSecretcheckKeys.test.ts, web3.test.ts +1Aikido only
#31Low4 exposed secretsSecret2fa.test.tsAikido only
#32Low1 exposed secretSecret2faSetupSpec.jsAikido only
#33Low1 exposed secretSecrettotpSetup.spec.tsAikido only
#34Low5 exposed secretsSecretcurrentUserSpec.js +1Aikido only
#35Low2 exposed secretsSecret2faSpec.js, 2fa.test.tsAikido only
#36Low6 exposed secretsSecretuser.test.ts, userApiSpec.jsAikido only

Codex — 20 findings

Severity
#SevFindingKey filesOverlap
#1HighUnpinned CI image actions receive repository token.github/workflows/image_actions.ymlAudn+Codex
#2HighUnpinned image workflow actions expose CI token.github/workflows/image_actions.ymlAudn+Codex
#3High2FA temporary JWTs accepted as bearer authserver.ts, lib/insecurity.tsAudn+Codex
#4HighGlobal forged-JWT registration enables account takeoverlib/insecurity.tsAudn+Codex
#5HighRelease tag command injection in legacy website workflow.github/workflows/update-news-www-legacy.ymlAudn+Codex
#6HighUnpinned npm installs in release and Docker buildspackage-lock.json, DockerfileAudn+Codex
#7HighChat order tool trusts unverified JWT identityroutes/chat.tsAudn+Codex
#8HighChat order tool trusts unsigned JWT identityroutes/chat.tsAudn+Codex
#9MediumUnbounded complaint similarity scan enables DoSroutes/verify.ts, models/complaint.tsCodex only
#10MediumLazy Web3 imports race creates duplicate listenersroutes/nftMint.ts, routes/web3Wallet.tsAudn+Codex
#11MediumLazy ethers import races Web3 listener creationroutes/nftMint.ts, routes/web3Wallet.tsAudn+Codex
#12MediumCI smoke test re-enables npm lifecycle scripts.github/workflows/ci.ymlAudn+Codex
#13MediumJunie skill curls untrusted reference URLs.junie/skills/add-reference/SKILL.mdCodex only
#14MediumUnsafe Junie curl crawling exposes local/internal resources.junie/skills/add-reference/SKILL.mdCodex only
#15MediumExternal Google Font leaks visitor metadataconfig/ctf.yml, index.htmlCodex only
#16LowUnconditional Google Fonts load leaks CTF visitor metadataserver.ts, index.htmlCodex only
#17LowWindows i18n restore uses Unix-only basename parsinglib/startup/restoreOverwrittenFilesWithOriginals.tsCodex only
#18InfoChallenge name mismatch hides Hacking Instructordata/static/challenges.ymlCodex only
#19InfoComplaint length test no longer checks max boundarycomplaint.component.spec.tsCodex only
#20InfoMissing snippet metadata now causes 500 errorsroutes/vulnCodeSnippet.tsCodex only

Recommended stack — where each scanner runs

Four gates from commit to main, ordered by cost and depth: cheap/fast/frequent first, expensive/live last. Mythos slots in as the deep whole-repo review before the merge, complementing Codex's fast diff scope; Audn stays at the merge-to-main gate as you called it.

Every commit / push
Aikido~52s
SAST + SCA + secrets + CI baseline
  • Fail on a new dependency CVE
  • Fail on a committed secret
Cheap enough for every push; the only SCA + secrets net.
→
PR opened
Codexlight
Diff-aware review of the changeset
  • Block introduced regressions
  • Attach the patch
Fast, per-PR; what did this change break.
→
PR review / pre-merge
Mythosmedium
Deep whole-repo static review
  • Surface DoS / robustness + logic
  • Whole-repo, reachability-aware
Catches what the diff scope misses — availability, IDOR, crashes.
→
Your call
Ready to merge → main
Audn~2h 28m
SAST + live red-team on a deployed preview
  • Block on a live-confirmed critical
The only exploit proof — last line before main.
⚑ Deploy the PR to a preview / staging env first, then point Audn at it.
→
On main / production
main
Keep the baseline live
  • Aikido continuous re-scan
  • Audn periodic re-run
New CVEs land after merge too.

Codex and Mythos overlap (both AI code review) but differ in scope: Codex is diff-scoped and fast (every PR), Mythos is whole-repo and deep (pre-merge or scheduled). If you run only one AI reviewer, Mythos gives breadth; Codex gives the "what this PR introduced" delta and a patch. Audn's ~2h 28m means the merge gate isn't instant — run it against the preview as soon as the PR is approved.