vulns.co
/
GKData.io MCP

Chain index

Each row is the gadget's own chain note. None linked means that gadget has no chains array.

GadgetBecomesNote
Open redirectOAuth / OIDC code leakPlant the redirect as redirect_uri or as the post-login next= so the IdP or app drops ?code= on your origin.
XSSIf the sink is location / href and javascript: or data: survives, it is an XSS gadget, not a redirect.
SSRFIf a backend follows the same parameter (webhooks, PDF, image, link-unfurl), it is server-side.
Token theftPassword-reset and magic-link flows that bounce through next= leak the token in Referer or the Location chain.
CORS reflectionAccount takeover / data readAttacker page on evil.com fetches https://api.target.com/me with credentials:include and reads the body.
CSRF+If ACAO reflects and methods include PUT/DELETE, it is CSRF with a response body, not just a fire-and-forget POST.
postMessage wildcardXSSdata.html or data.url lands in innerHTML, document.write, or a script src.
ATOdata.token / data.user is applied to localStorage or a parent auth store.
UXSS-liteOpener from a target page you can XSS (or an open redirect) posts into a privileged listener on another origin of the same program.
Unkeyed header / cache keyStored XSSPoison a cached HTML/JS page with a reflected header that writes a script src or a base href.
Open redirect at scalePoison Location or asset URLs so every cache hit leaves the site.
Web cache deceptionPath mapping like /account/settings/x.css so a personalised page is stored as a static asset.
Debug / actuator / env endpointRCE / SSRFSpring gateway + heapdump, Actuator env + refresh, GraphQL debug to nested SSRF.
Secret leakenv, config, .git, source maps, firebase config, AWS keys in JS.
Auth bypassDebug routes skip the auth middleware the public routes use.
Leaked token in URL, JS, or RefererATOOpen redirect or XSS on a page that receives the token, or Referer leak to an attacker-controlled image.
API takeoverBearer token in a JS bundle or HAR used against the live API.
IDOR parameterMass data accessPredictable IDs plus no rate limit plus a list endpoint or a range.
ATOChange email / password / 2FA on another userId.
Privilege escalationrole, isAdmin, organisationId in the same body as a user-owned object.
DOM sink (innerHTML / html() / v-html)Reflected XSSlocation.hash, query, postMessage, or document.referrer reaches the sink.
Stored XSSProfile fields, comments, filenames, or webhook payloads are stored then rendered.
CSP bypassIf a gadget already executes, look for nonce reuse, JSONP, or Angular/template sinks that CSP missed.
JSONP / callback parameterXSScallback=alert(1)// or callback=<script> if content-type is HTML.
Data theft with cookiesJSONP is a CORS bypass: a foreign page includes the script and reads the padded JSON in a stolen-callback function.
Framable authenticated pageCSRF-like state changeOverlay the target button under an attacker UI. Victim clicks.
XS-LeakFrame counting, window length, or timing to infer login state or search hits.
Cookie on parent domainATO via sibling XSSXSS on docs.target.com reads document.cookie for .target.com and posts it.
ATO via takeoverDangling CNAME + cookie on parent domain = classic.
Public source mapHidden API / IDOROriginal source names the internal GraphQL mutations and admin routes the minified bundle hid.
SecretMaps sometimes contain .env leftovers, comments with tokens, or staging URLs.
Prototype pollution gadgetXSSPollute Object.prototype to turn a safe HTML assignment into a sink (e.g. sanitizer options, script src).
RCEServer-side: pollute env, execPath, shell, or template engine options.
WebSocket IDOR / missing authMass data accessGuess channel IDs or replay another user's subscribe message.
Stored XSSIf the client renders WS payloads as HTML, you have a stored XSS broadcast.
Host header / password reset poisoningATOReset email points at attacker host; victim clicks; token lands on you.
Cache poisonHost is unkeyed; HTML with attacker asset hosts is cached for everyone.
CRLF / header injectionSession fixationInject Set-Cookie.
XSSInject a second response body with HTML, or a Location: javascript:.
Cache poisonSplit so a CDN caches the injected body under a popular key.
OAuth redirect_uri mismatchATOVictim authorises; code or token is delivered to an origin you control; exchange it.
Account linkingPre-account takeover: register with victim email, then link via OAuth without verifying.
JWT algorithm / key confusionPriv-esc / ATOForge sub / role / tenant and replay.
SSRFjku / x5u URL is fetched server-side.
Server-side URL fetch (unfurl / PDF / image / webhook)Cloud metadata169.254.169.254 / metadata.google.internal / IMDS. Prefer a canary first.
RCEfile://, gopher://, dict://, or a secondary parser bug in the fetcher (XXE, ImageTragick-class).
XSSThe fetched content is inlined into HTML (stored XSS via SVG/HTML).
File upload gadgetStored XSSSVG or HTML served from the app origin or a cookied CDN.
RCEZip slip, ImageMagick, Office macros on a backend converter, template upload.
Race / limit overrunFinancialApply the same coupon or withdraw the same balance N times.
ATORace the email-change vs verify, or brute OTP without the rate limit incrementing.
Mass assignment / extra JSON fieldPriv-escisAdmin true or role=admin on your own object.
ATOemail verified true, or set someone else's email then reset.
Weak CSP / missing nonceXSSJSONP on an allowed origin, Angular sandbox gadgets, nonce leakage into a page you inject, or 'unsafe-inline'.
Well-known / security.txt / OIDC discoveryOAuth attacksDiscovery gives you the authorize / token / jwks URLs the SPA hid.
Mobile deep linksAASA / assetlinks list the real app IDs and paths.
Email / SMS parser confusionATO / pre-ATOCreate an account the victim later SSO-links, or intercept the reset.
CSRF without a real origin checkAccount takeoverChange the victim's email or OAuth link from an attacker page, then reset.
Privilege escalationInvite-accept or role-grant endpoints that only check the session cookie.
Integrity / moneyPayout account, subscription, or transfer POSTs with SameSite=None or a subdomain cookie.
Server-side template evaluationRCEEngine exposes a sandbox escape or a known gadget (Jinja __class__, Freemarker Execute). Stop at the primitive unless the program allows a bounded proof.
SSRF / file readTemplate includes or fetch helpers that take a URL or path from the same input.
XSSIf evaluation is client-side (Mustache in the browser) it is XSS, not SSTI. Name it correctly.
XML external entity / DTD fetchSSRFExternal DTD or entity URL is fetched by the server. Canary first.
Blind file readOnly after the canary, and only if policy allows a non-sensitive file you own or a harmless path the program lists.
DoSRecursive entities. Out of scope on almost every program. Do not.
GraphQL node(id) / alias batchIDOR / BOLASwap a global ID from account A into a query as account B. Export and search fields are the usual amplifiers.
BFLAAdmin mutations still in the schema. The UI hid the button; the schema did not.
Rate-limit skipOne HTTP request, hundreds of aliases. Lockout and billing counters that key on request count lose.
HTTP request smuggling desyncCache poison / XSSSmuggled request writes a response that the next user, or the cache, receives.
Credential theftCapture a victim request that was appended onto your smuggled prefix. Do not do this against real users. Lab or two sessions you own.
Bypass ACLInner request hits an internal route the front-end would have blocked.
SAML ACS / recipient confusionATOReplay or re-target an assertion at a different ACS or tenant that still verifies the signature.
Account linkingEmail claim from the IdP overwrites a local account with no verification.
XXEThe same XML parser that verifies the assertion may still load a DTD.
DOM clobbering named elementDOM XSSClobbered location or callback is concatenated into a sink the sanitizer thought was safe.
Prototype pollution gadgetNamed properties on window collide with lib defaults.
CSP bypass liteClobber a nonce-bearing script's lookup so a second injection runs.
TOCTOU / last-write raceLimit overrunN parallel redeems, one lockout increment.
ATORace email-change confirm vs session issue, or MFA disable vs login.
IntegrityTwo transfers both read the same balance.
Passkey recovery skips WebAuthnAccount takeoverPrimary login requires a passkey, but recovery still issues a full session for an account you own.
Durable accessA session that never completed WebAuthn is allowed to register a new passkey, so the strong factor is added by whoever holds the weak session.
OAuth mix-up across authorization serversAuthorization code theftThe client redeems the code at the issuer named by the response rather than the issuer that started the request, so the code and the PKCE verifier are sent to the wrong token endpoint.
Account linkingA response from one authorization server is accepted as login for another because issuer, audience, and state are not compared to the request that started the flow.
DPoP sender constraint droppedToken replayA token that was issued with a DPoP binding is accepted with no proof, so possession of the token is enough.
Proof reuseThe server accepts a proof for a different method, URI, or access token than the one it was built for.
Tenant id trusted by an exportCross-tenant readTwo tenants you belong to, and the export for one returns rows from the other because the worker trusted the supplied tenant id.
Shared artifactThe file is stored or mailed under a path or link that does not re-check the tenant, so the cross-tenant result outlives the API call.
Web cache deception via path confusionPrivate data disclosureAn authenticated client you control requests the confusing path, the cache stores the private body, and a second clean client receives that body.
Credential or link leakThe stored body includes a still-valid link or anti-forgery value that was meant only for the authenticated caller.
Cookie scoped to the parent domainSibling takeoverA subdomain you can script or reclaim receives the parent-scoped session cookie, or the browser sends it there.
Cookie shadowingA sibling is allowed to set the same parent-scoped name, and the app prefers the value the sibling wrote.
Partitioned cookie gapCross-site session useAn embed on another site still receives the credential cookie because it is not Partitioned and the browser has not blocked that send.
Jar confusionThe server accepts either the Partitioned cookie or an unpartitioned cookie of the same name, so the two jars disagree and the app follows the wrong one.
Refresh token survives logoutSession survives logoutAfter logout on an account you own, the refresh token still returns a new access token.
Session survives password changeA refresh token issued before the password change, or before log-out-everywhere, is still accepted.
pull_request_target checks out pull request codeSecret exposureThe workflow uses pull_request_target, checks out pull request code, and that code runs where base-repository secrets are available.
Repository writeThe same checkout runs with the base repository token, so pull request code acts as the repository rather than as the fork.
MCP token wider than the toolCross-tool accessA token minted for one tool is accepted by another tool whose audience or scope is broader than the call the user invoked.
Cross-tenant useThe server uses a static credential for retrieval or API calls and does not constrain those calls to the caller's tenant.
RAG chunk from another tenantCross-tenant disclosureA retrieval for a tenant you own returns a chunk stored for a different tenant because the query filter omits tenant.
Context bleedThe tenant filter is applied after the top-k cut, so another tenant's nearer chunk fills the window that is sent onward.
App link host claimAuth callback on the wrong hostThe association file or path prefix includes a host you can serve, and the app treats that host as a trusted auth callback.
Unverified scheme fallbackThe https claim is checked, but the same callback is registered as a custom scheme that any installed app can claim.
Persisted query allowlist bypassAllowlist bypassThe server executes a full query document when the hash is unknown, or registers that document for later, instead of rejecting it.
Cross-caller executionA persisted query saved by a more privileged user or another tenant is executed by a different caller because the store is global and the operation authorization is not re-checked.
Webhook signature is optionalForged state changeThe handler applies a role, billing, or provision change when the signature header is absent or the secret is empty.
Fail openA verifier error, a clock check, or a test-mode flag skips verification and the event is still applied.
Archive entry escapes the extract rootFile overwriteAn archive you created contains an entry that resolves outside the extract root, and the service writes it on a path it later reads.
Link followA link entry points outside the root and the extractor or a later read follows it.
Feature flag hides a live routeBroken function-level authorizationThe handler runs for an account you own whose flag is off, and the flag was the only gate.
Fail openWhen the flag service times out or errors, the route defaults to enabled and the same gate disappears.

Open the gadget for the places to look. This index does not add a procedure.