This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 0.2.0, and Reverts across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds interactive DOM/reflected XSS oracle in dast module. Adds interactive DOM/reflected XSS oracle in dast module. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes DAST to return DOM XSS findings on timeout instead of discarding them. Fixes DAST to return DOM XSS findings on timeout instead of discarding them. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Reverts NoSQL oracle tightening, restoring prior detection behavior in dast. Reverts NoSQL oracle tightening, restoring prior detection behavior in dast. Source: llm_adapter@2026-07-15 Confidence: low |
— |
Full changelog
0.2.0 (2026-07-12)
Features
Bug Fixes
- dast: return DOM XSS findings on timeout instead of discarding them (3c979ad)
- dast: tighten NoSQL oracle to kill false positives (#5) (f899664)
Documentation
- benchmarks: document the must-detect regression guard (d8e1150)
- benchmarks: Juice Shop url-only recall 33% -> 36% after XSS fix (4b8b16a)
- benchmarks: make OWASP Juice Shop reproducible + correct the numbers (be9af0f)
- flag NoSQL injection as a known false-positive-prone class (#5) (c334c3e)
Reverts
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About isitsecure
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]