Demo AppsSource Code & Vulnerability Inspector
Demo Target Code
Inspect the source code behind the BreachLabs demo sandbox targets across Flask, Django, and Node.js. Explore intentional syntax defects, subtle & severe vulnerabilities, SAST/DAST markers, and AI-generated remediation diffs.
TARGET ENVIRONMENT
PYTHON 3.14 / FLASK
Flask Vulnerable Store
Lightweight Python web app containing classic OWASP Top 10 vulnerabilities including raw SQL string interpolation, unescaped HTML reflection, and hardcoded JWT secrets.
PROJECT FILE TREE
DETECTED FLAWS IN FILE
3 Findings
HIGH SEVERITY
BL-SAST-001: SQL Injection via String Concatenation
CWE-89
User-controlled input is formatted directly into a raw SQL query string without parameterization or sanitization, allowing attackers to manipulate queries and bypass authentication or exfiltrate database records.
VULNERABLE SOURCE (BEFORE)
query = f"SELECT * FROM products WHERE name LIKE '%{query}%'"
BREACHLABS AI REMEDIATION (AFTER)
cursor.execute("SELECT * FROM products WHERE name LIKE ?", (f"%{query}%",))
Verified fix stops exploit replay while maintaining application test suite passing.
Test in Interactive Sandbox ›