-
Notifications
You must be signed in to change notification settings - Fork 0
Pull requests: Contrast-Security-OSS/cargocats-smartfix-demo
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Fix: Unsafe Code Execution from Untrusted Sources on "/generate-label" page
contrast-vuln-id:VULN-V3S7-W29G-SRRY-PR83
Vulnerability identified by Contrast AI SmartFix
#13
opened Dec 9, 2025 by
github-actions
bot
Loading…
Fix: Untrusted Deserialization from Request Body on "/api/addresses/import" page
contrast-vuln-id:VULN-6IB3-CY03-MYQN-MR7G
Vulnerability identified by Contrast AI SmartFix
#12
opened Dec 9, 2025 by
github-actions
bot
Loading…
Fix: OS Command Injection from Request Body on "/testConnection" page
contrast-vuln-id:VULN-EOC6-TZ8F-JPZC-NFC0
Vulnerability identified by Contrast AI SmartFix
#11
opened Dec 9, 2025 by
github-actions
bot
Loading…
Fix: Path Traversal from "path" Parameter on "/getphoto" page
contrast-vuln-id:VULN-DAS4-PJU5-XEC0-USGG
Vulnerability identified by Contrast AI SmartFix
#10
opened Dec 9, 2025 by
github-actions
bot
Loading…
Fix: JNDI Injection from "username" Parameter in org.springframework.security.web.authentication.Username
contrast-vuln-id:VULN-KZSH-ZCSL-GXOF-PCH2
Vulnerability identified by Contrast AI SmartFix
#9
opened Dec 9, 2025 by
github-actions
bot
Loading…
Fix: SQL Injection from "creditCard" Parameter, "shipmentId" Parameter on "/payments" page
contrast-vuln-id:VULN-DVVZ-T0I5-3R5H-HDBI
Vulnerability identified by Contrast AI SmartFix
#8
opened Dec 9, 2025 by
github-actions
bot
Loading…
ProTip!
Add no:assignee to see everything that’s not assigned.