This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+9 more
Summary
AI summaryUpdates π‘οΈ New Vulnerabilities Added, π₯ Highlights, and NEW across a mixed release.
Full changelog
This release introduces major enhancements to VulnerableApp, including the addition of LLM-focused security labs, new vulnerabilities, and improvements across the platform.
π₯ Highlights
π€ Introducing LLMForge (NEW)
We are excited to launch LLMForge, a new application within VulnerableApp focused on LLM (Large Language Model) security vulnerabilities.
LLMForge enables learners and security researchers to:
Explore real-world LLM attack vectors
Understand emerging risks like prompt injection, data leakage, and unsafe tool usage
Practice exploiting and mitigating vulnerabilities in AI-powered applications
LLMForge is accessible via the Docker setup. Simply run:
docker-compose up -d
and access VulnerableApp along with LLMForge at:
http://localhost
This marks a significant step in expanding VulnerableApp beyond traditional web security into AI security education.
π‘οΈ New Vulnerabilities Added
π IDOR (Insecure Direct Object Reference)
Added a complete IDOR vulnerability lab
Includes multiple levels for progressive learning
Refactored for better clarity and extensibility
πͺ Clickjacking
Introduced a new Clickjacking vulnerability scenario
Includes both vulnerable and fixed implementations for comparison
𧬠LDAP Injection
New LDAP Injection vulnerability added
Improved level design and feedback based on testing iterations
π§° Improvements & Fixes
β
Fixed Clickjacking vulnerability implementation in modern UI
β
Added ping utility to Docker base image (fixes Command Injection lab issues)
β
Improved documentation for modern UI testing workflows
β
Updated internationalized README files to align with the English version
β
General code refactoring and stability improvements across vulnerability modules
π₯ New Contributors
Weβre thrilled to welcome new contributors to the project π
@Roshan1299 β Clickjacking vulnerability
@monssefbaakka β i18n documentation updates
@PrakarshSrivastav β Testing scripts & documentation
@zeel2104 β Docker fixes for command injection
Special Mention
Special thanks to @antriksh-9 and @Roshan1299 for their outstanding contributions to this release.
@antriksh-9 delivered high-impact work by building core vulnerability labs including IDOR and LDAP Injection, significantly strengthening the platformβs security coverage.
@Roshan1299 contributed the Clickjacking vulnerability, adding important client-side attack scenarios to the application.
π¦ Full Changelog
π https://github.com/SasanLabs/VulnerableApp/compare/1.13...2.0.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About VulnerableApp
All releases βRelated context
Related tools
Beta — feedback welcome: [email protected]