DemoDeterministic Assessment Engine
DEMO-0001
Interactive illustrative assessment replay · breachlabs-demo · 4820ms · 12 routes mapped
COMPLETED
Deterministic Replay
Discovered Findings
3
2 Verified · 1 Investigating
Verification Rate
100%
Zero unproven claims
Target Execution Time
4820ms
Deterministic pipeline replay
Mapped Surface
12
Routes, forms & APIs
01[00:00.120] INTAKE: Repository checked out at revision
a9f82d1 (clean sandbox)02[00:01.450] DISCOVER: Enumerated 14 HTTP routes, 3 forms, 9 JSON endpoints
03[00:02.810] SAST: Taint sink in search.py:38 -> direct string concatenation into SQL query
04[00:03.200] AGENT: Correlated route GET /search?q= with unvalidated query parameter
05[00:04.110] VERIFY: Dispatched deterministic probe -> Syntax verification payload confirmed BL-DEMO-001
06[00:04.820] SUMMARY: Assessment complete · 3 findings recorded in append-only evidence store
BL-DEMO-001
VERIFIED
SQL injection in search parameter
SeverityHIGH
ConfidenceVERIFIED
Surface
GET /search?q=
Click to inspect
Evidence & Fix →
BL-DEMO-002
VERIFIED
Reflected XSS in comment field
SeverityHIGH
ConfidenceVERIFIED
Surface
POST /comments
Click to inspect
Evidence & Fix →
BL-DEMO-003
VERIFIED
Missing security response headers
SeverityMEDIUM
ConfidenceVERIFIED
Surface
GET /
Click to inspect
Evidence & Fix →
BL-DEMO-001
VERIFIED
CWE-89: SQL Injection
SQL injection in search parameter
Surface:
GET /search?q=
1. Vulnerable Code Context
36def search_products(request):
37 term = request.args.get('q', '')
38 query = "SELECT * FROM items WHERE name = '" + term + "'"
39 return db.engine.execute(query).fetchall()
2. Evidence Provenance Chain
search.py:38 — AST Taint analysis sink
SAST
GET /search?q='%20OR%20'1'='1 → HTTP 200 with full DB dump
DAST PROBE
Unparameterized SQL executed in 2 surrounding helper calls
CORRELATION
3. AI Security Analysis
The q query parameter is read directly from untrusted user input and concatenated without sanitization or SQL parameter binding. The verification probe confirmed that arbitrary SQL syntax executes against the SQLite datastore.
4. Remediation Patch
1- query = "SELECT * FROM items WHERE name = '" + term + "'"
2- return db.engine.execute(query).fetchall()
3+ query = "SELECT * FROM items WHERE name = ?"
4+ return db.engine.execute(query, (term,)).fetchall()
Retest Verified: Replaying probe payload against patched code resulted in HTTP 200 with zero injected query syntax execution. Finding marked RESOLVED.
NO FINDINGS MATCH THIS FILTER
3 of 3 findings shown. Assessment replay is fully deterministic.
01# Security Assessment Report — breachlabs-demo
02**Assessment ID:** DEMO-0001 | **Status:** COMPLETED | **Date:** 2026-09-19
03---
04## 1. Executive Summary
05BreachLabs completed an autonomous security assessment of the target environment.
06Total routes mapped: **14** | Discovered findings: **3** | Verified exploits: **2** | Unconfirmed: **0**
07---
08## 2. Verified Findings
09### [BL-DEMO-001] SQL Injection in Search Parameter (Severity: HIGH, CVSS: 8.4)
10- **Surface:** `GET /search?q=`
11- **Source Context:** `search.py:38`
12- **Evidence:** Probe payload confirmed unparameterized SQL execution returning database records.
13- **Remediation:** Bind user parameter using prepared statements `cursor.execute(query, (term,))`.
14- **Retest Status:** VERIFIED RESOLVED after patch application.
15### [BL-DEMO-002] Reflected XSS in Comment Field (Severity: HIGH, CVSS: 7.2)
16- **Surface:** `POST /comments`
17- **Evidence:** Unescaped HTML rendering in comment stream verified via automated browser probe.
18---
19## 3. Stated Limitations
20Automated assessment covers scoped surface only. Logic flaws outside tested paths are not assessed.
01{
02 "assessment_id": "DEMO-0001",
03 "status": "completed",
04 "target": "breachlabs-demo",
05 "duration_ms": 4820,
06 "routes_discovered": 12,
07 "pipeline_stages": ["discovery", "sast", "dast", "agent_investigation", "verification", "retest"],
08 "findings_count": 3,
09 "findings_verified": 2,
10 "verification_rate": 1.0
11}