Chain index
Each row is the gadget's own chain note. None linked means that gadget has no chains array.
| Gadget | Becomes | Note |
|---|---|---|
| Open redirect | OAuth / OIDC code leak | Plant the redirect as redirect_uri or as the post-login next= so the IdP or app drops ?code= on your origin. |
| XSS | If the sink is location / href and javascript: or data: survives, it is an XSS gadget, not a redirect. | |
| SSRF | If a backend follows the same parameter (webhooks, PDF, image, link-unfurl), it is server-side. | |
| Token theft | Password-reset and magic-link flows that bounce through next= leak the token in Referer or the Location chain. | |
| CORS reflection | Account takeover / data read | Attacker page on evil.com fetches https://api.target.com/me with credentials:include and reads the body. |
| CSRF+ | If ACAO reflects and methods include PUT/DELETE, it is CSRF with a response body, not just a fire-and-forget POST. | |
| postMessage wildcard | XSS | data.html or data.url lands in innerHTML, document.write, or a script src. |
| ATO | data.token / data.user is applied to localStorage or a parent auth store. | |
| UXSS-lite | Opener from a target page you can XSS (or an open redirect) posts into a privileged listener on another origin of the same program. | |
| Unkeyed header / cache key | Stored XSS | Poison a cached HTML/JS page with a reflected header that writes a script src or a base href. |
| Open redirect at scale | Poison Location or asset URLs so every cache hit leaves the site. | |
| Web cache deception | Path mapping like /account/settings/x.css so a personalised page is stored as a static asset. | |
| Debug / actuator / env endpoint | RCE / SSRF | Spring gateway + heapdump, Actuator env + refresh, GraphQL debug to nested SSRF. |
| Secret leak | env, config, .git, source maps, firebase config, AWS keys in JS. | |
| Auth bypass | Debug routes skip the auth middleware the public routes use. | |
| Leaked token in URL, JS, or Referer | ATO | Open redirect or XSS on a page that receives the token, or Referer leak to an attacker-controlled image. |
| API takeover | Bearer token in a JS bundle or HAR used against the live API. | |
| IDOR parameter | Mass data access | Predictable IDs plus no rate limit plus a list endpoint or a range. |
| ATO | Change email / password / 2FA on another userId. | |
| Privilege escalation | role, isAdmin, organisationId in the same body as a user-owned object. | |
| DOM sink (innerHTML / html() / v-html) | Reflected XSS | location.hash, query, postMessage, or document.referrer reaches the sink. |
| Stored XSS | Profile fields, comments, filenames, or webhook payloads are stored then rendered. | |
| CSP bypass | If a gadget already executes, look for nonce reuse, JSONP, or Angular/template sinks that CSP missed. | |
| JSONP / callback parameter | XSS | callback=alert(1)// or callback=<script> if content-type is HTML. |
| Data theft with cookies | JSONP is a CORS bypass: a foreign page includes the script and reads the padded JSON in a stolen-callback function. | |
| Framable authenticated page | CSRF-like state change | Overlay the target button under an attacker UI. Victim clicks. |
| XS-Leak | Frame counting, window length, or timing to infer login state or search hits. | |
| Cookie on parent domain | ATO via sibling XSS | XSS on docs.target.com reads document.cookie for .target.com and posts it. |
| ATO via takeover | Dangling CNAME + cookie on parent domain = classic. | |
| Public source map | Hidden API / IDOR | Original source names the internal GraphQL mutations and admin routes the minified bundle hid. |
| Secret | Maps sometimes contain .env leftovers, comments with tokens, or staging URLs. | |
| Prototype pollution gadget | XSS | Pollute Object.prototype to turn a safe HTML assignment into a sink (e.g. sanitizer options, script src). |
| RCE | Server-side: pollute env, execPath, shell, or template engine options. | |
| WebSocket IDOR / missing auth | Mass data access | Guess channel IDs or replay another user's subscribe message. |
| Stored XSS | If the client renders WS payloads as HTML, you have a stored XSS broadcast. | |
| Host header / password reset poisoning | ATO | Reset email points at attacker host; victim clicks; token lands on you. |
| Cache poison | Host is unkeyed; HTML with attacker asset hosts is cached for everyone. | |
| CRLF / header injection | Session fixation | Inject Set-Cookie. |
| XSS | Inject a second response body with HTML, or a Location: javascript:. | |
| Cache poison | Split so a CDN caches the injected body under a popular key. | |
| OAuth redirect_uri mismatch | ATO | Victim authorises; code or token is delivered to an origin you control; exchange it. |
| Account linking | Pre-account takeover: register with victim email, then link via OAuth without verifying. | |
| JWT algorithm / key confusion | Priv-esc / ATO | Forge sub / role / tenant and replay. |
| SSRF | jku / x5u URL is fetched server-side. | |
| Server-side URL fetch (unfurl / PDF / image / webhook) | Cloud metadata | 169.254.169.254 / metadata.google.internal / IMDS. Prefer a canary first. |
| RCE | file://, gopher://, dict://, or a secondary parser bug in the fetcher (XXE, ImageTragick-class). | |
| XSS | The fetched content is inlined into HTML (stored XSS via SVG/HTML). | |
| File upload gadget | Stored XSS | SVG or HTML served from the app origin or a cookied CDN. |
| RCE | Zip slip, ImageMagick, Office macros on a backend converter, template upload. | |
| Race / limit overrun | Financial | Apply the same coupon or withdraw the same balance N times. |
| ATO | Race the email-change vs verify, or brute OTP without the rate limit incrementing. | |
| Mass assignment / extra JSON field | Priv-esc | isAdmin true or role=admin on your own object. |
| ATO | email verified true, or set someone else's email then reset. | |
| Weak CSP / missing nonce | XSS | JSONP on an allowed origin, Angular sandbox gadgets, nonce leakage into a page you inject, or 'unsafe-inline'. |
| Well-known / security.txt / OIDC discovery | OAuth attacks | Discovery gives you the authorize / token / jwks URLs the SPA hid. |
| Mobile deep links | AASA / assetlinks list the real app IDs and paths. | |
| Email / SMS parser confusion | ATO / pre-ATO | Create an account the victim later SSO-links, or intercept the reset. |
| CSRF without a real origin check | Account takeover | Change the victim's email or OAuth link from an attacker page, then reset. |
| Privilege escalation | Invite-accept or role-grant endpoints that only check the session cookie. | |
| Integrity / money | Payout account, subscription, or transfer POSTs with SameSite=None or a subdomain cookie. | |
| Server-side template evaluation | RCE | Engine exposes a sandbox escape or a known gadget (Jinja __class__, Freemarker Execute). Stop at the primitive unless the program allows a bounded proof. |
| SSRF / file read | Template includes or fetch helpers that take a URL or path from the same input. | |
| XSS | If evaluation is client-side (Mustache in the browser) it is XSS, not SSTI. Name it correctly. | |
| XML external entity / DTD fetch | SSRF | External DTD or entity URL is fetched by the server. Canary first. |
| Blind file read | Only after the canary, and only if policy allows a non-sensitive file you own or a harmless path the program lists. | |
| DoS | Recursive entities. Out of scope on almost every program. Do not. | |
| GraphQL node(id) / alias batch | IDOR / BOLA | Swap a global ID from account A into a query as account B. Export and search fields are the usual amplifiers. |
| BFLA | Admin mutations still in the schema. The UI hid the button; the schema did not. | |
| Rate-limit skip | One HTTP request, hundreds of aliases. Lockout and billing counters that key on request count lose. | |
| HTTP request smuggling desync | Cache poison / XSS | Smuggled request writes a response that the next user, or the cache, receives. |
| Credential theft | Capture a victim request that was appended onto your smuggled prefix. Do not do this against real users. Lab or two sessions you own. | |
| Bypass ACL | Inner request hits an internal route the front-end would have blocked. | |
| SAML ACS / recipient confusion | ATO | Replay or re-target an assertion at a different ACS or tenant that still verifies the signature. |
| Account linking | Email claim from the IdP overwrites a local account with no verification. | |
| XXE | The same XML parser that verifies the assertion may still load a DTD. | |
| DOM clobbering named element | DOM XSS | Clobbered location or callback is concatenated into a sink the sanitizer thought was safe. |
| Prototype pollution gadget | Named properties on window collide with lib defaults. | |
| CSP bypass lite | Clobber a nonce-bearing script's lookup so a second injection runs. | |
| TOCTOU / last-write race | Limit overrun | N parallel redeems, one lockout increment. |
| ATO | Race email-change confirm vs session issue, or MFA disable vs login. | |
| Integrity | Two transfers both read the same balance. | |
| Passkey recovery skips WebAuthn | Account takeover | Primary login requires a passkey, but recovery still issues a full session for an account you own. |
| Durable access | A session that never completed WebAuthn is allowed to register a new passkey, so the strong factor is added by whoever holds the weak session. | |
| OAuth mix-up across authorization servers | Authorization code theft | The client redeems the code at the issuer named by the response rather than the issuer that started the request, so the code and the PKCE verifier are sent to the wrong token endpoint. |
| Account linking | A response from one authorization server is accepted as login for another because issuer, audience, and state are not compared to the request that started the flow. | |
| DPoP sender constraint dropped | Token replay | A token that was issued with a DPoP binding is accepted with no proof, so possession of the token is enough. |
| Proof reuse | The server accepts a proof for a different method, URI, or access token than the one it was built for. | |
| Tenant id trusted by an export | Cross-tenant read | Two tenants you belong to, and the export for one returns rows from the other because the worker trusted the supplied tenant id. |
| Shared artifact | The file is stored or mailed under a path or link that does not re-check the tenant, so the cross-tenant result outlives the API call. | |
| Web cache deception via path confusion | Private data disclosure | An authenticated client you control requests the confusing path, the cache stores the private body, and a second clean client receives that body. |
| Credential or link leak | The stored body includes a still-valid link or anti-forgery value that was meant only for the authenticated caller. | |
| Cookie scoped to the parent domain | Sibling takeover | A subdomain you can script or reclaim receives the parent-scoped session cookie, or the browser sends it there. |
| Cookie shadowing | A sibling is allowed to set the same parent-scoped name, and the app prefers the value the sibling wrote. | |
| Partitioned cookie gap | Cross-site session use | An embed on another site still receives the credential cookie because it is not Partitioned and the browser has not blocked that send. |
| Jar confusion | The server accepts either the Partitioned cookie or an unpartitioned cookie of the same name, so the two jars disagree and the app follows the wrong one. | |
| Refresh token survives logout | Session survives logout | After logout on an account you own, the refresh token still returns a new access token. |
| Session survives password change | A refresh token issued before the password change, or before log-out-everywhere, is still accepted. | |
| pull_request_target checks out pull request code | Secret exposure | The workflow uses pull_request_target, checks out pull request code, and that code runs where base-repository secrets are available. |
| Repository write | The same checkout runs with the base repository token, so pull request code acts as the repository rather than as the fork. | |
| MCP token wider than the tool | Cross-tool access | A token minted for one tool is accepted by another tool whose audience or scope is broader than the call the user invoked. |
| Cross-tenant use | The server uses a static credential for retrieval or API calls and does not constrain those calls to the caller's tenant. | |
| RAG chunk from another tenant | Cross-tenant disclosure | A retrieval for a tenant you own returns a chunk stored for a different tenant because the query filter omits tenant. |
| Context bleed | The tenant filter is applied after the top-k cut, so another tenant's nearer chunk fills the window that is sent onward. | |
| App link host claim | Auth callback on the wrong host | The association file or path prefix includes a host you can serve, and the app treats that host as a trusted auth callback. |
| Unverified scheme fallback | The https claim is checked, but the same callback is registered as a custom scheme that any installed app can claim. | |
| Persisted query allowlist bypass | Allowlist bypass | The server executes a full query document when the hash is unknown, or registers that document for later, instead of rejecting it. |
| Cross-caller execution | A persisted query saved by a more privileged user or another tenant is executed by a different caller because the store is global and the operation authorization is not re-checked. | |
| Webhook signature is optional | Forged state change | The handler applies a role, billing, or provision change when the signature header is absent or the secret is empty. |
| Fail open | A verifier error, a clock check, or a test-mode flag skips verification and the event is still applied. | |
| Archive entry escapes the extract root | File overwrite | An archive you created contains an entry that resolves outside the extract root, and the service writes it on a path it later reads. |
| Link follow | A link entry points outside the root and the extractor or a later read follows it. | |
| Feature flag hides a live route | Broken function-level authorization | The handler runs for an account you own whose flag is off, and the flag was the only gate. |
| Fail open | When the flag service times out or errors, the route defaults to enabled and the same gate disappears. |
Open the gadget for the places to look. This index does not add a procedure.