Home Product Architecture Security Capabilities Install MCP & Skills
DEMO EXPERIENCES ⚡ Interactive Security Demo 🔍 View Demo Code (Syntax Highlighted)
About
Demo AppsSource Code & Vulnerability Inspector

Demo Target Code

Inspect the source code behind the BreachLabs demo sandbox targets across Flask, Django, and Node.js. Explore intentional syntax defects, subtle & severe vulnerabilities, SAST/DAST markers, and AI-generated remediation diffs.

Framework Target:
TARGET ENVIRONMENT PYTHON 3.14 / FLASK
Flask Vulnerable Store

Lightweight Python web app containing classic OWASP Top 10 vulnerabilities including raw SQL string interpolation, unescaped HTML reflection, and hardcoded JWT secrets.

PROJECT FILE TREE
DETECTED FLAWS IN FILE 3 Findings
vulnerable_app.py
142 lines · Python
HIGH SEVERITY BL-SAST-001: SQL Injection via String Concatenation
CWE-89

User-controlled input is formatted directly into a raw SQL query string without parameterization or sanitization, allowing attackers to manipulate queries and bypass authentication or exfiltrate database records.

VULNERABLE SOURCE (BEFORE)
query = f"SELECT * FROM products WHERE name LIKE '%{query}%'"
BREACHLABS AI REMEDIATION (AFTER)
cursor.execute("SELECT * FROM products WHERE name LIKE ?", (f"%{query}%",))
Verified fix stops exploit replay while maintaining application test suite passing. Test in Interactive Sandbox ›