Skip to content

VulnerableApp

v2.0.1 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’

✓ No known CVEs patched in this version

Topics

security burpsuite css java javascript learn-security
+9 more
owasp owasp-zap payload-testing practice-hacking spring-boot test-vulnerability-scanning-tools vulnerability vulnerability-scanning vulnerable-application

Summary

AI summary

Updates πŸ›‘οΈ New Vulnerabilities Added, πŸ”₯ Highlights, and NEW across a mixed release.

Full changelog

This release introduces major enhancements to VulnerableApp, including the addition of LLM-focused security labs, new vulnerabilities, and improvements across the platform.

πŸ”₯ Highlights

πŸ€– Introducing LLMForge (NEW)

We are excited to launch LLMForge, a new application within VulnerableApp focused on LLM (Large Language Model) security vulnerabilities.

LLMForge enables learners and security researchers to:

Explore real-world LLM attack vectors
Understand emerging risks like prompt injection, data leakage, and unsafe tool usage
Practice exploiting and mitigating vulnerabilities in AI-powered applications

LLMForge is accessible via the Docker setup. Simply run:
docker-compose up -d
and access VulnerableApp along with LLMForge at:
http://localhost

This marks a significant step in expanding VulnerableApp beyond traditional web security into AI security education.

πŸ›‘οΈ New Vulnerabilities Added

πŸ”“ IDOR (Insecure Direct Object Reference)

Added a complete IDOR vulnerability lab
Includes multiple levels for progressive learning
Refactored for better clarity and extensibility

πŸͺŸ Clickjacking

Introduced a new Clickjacking vulnerability scenario
Includes both vulnerable and fixed implementations for comparison

🧬 LDAP Injection

New LDAP Injection vulnerability added
Improved level design and feedback based on testing iterations

🧰 Improvements & Fixes

βœ… Fixed Clickjacking vulnerability implementation in modern UI
βœ… Added ping utility to Docker base image (fixes Command Injection lab issues)
βœ… Improved documentation for modern UI testing workflows
βœ… Updated internationalized README files to align with the English version
βœ… General code refactoring and stability improvements across vulnerability modules

πŸ‘₯ New Contributors

We’re thrilled to welcome new contributors to the project πŸŽ‰
@Roshan1299 – Clickjacking vulnerability
@monssefbaakka – i18n documentation updates
@PrakarshSrivastav – Testing scripts & documentation
@zeel2104 – Docker fixes for command injection

Special Mention

Special thanks to @antriksh-9 and @Roshan1299 for their outstanding contributions to this release.
@antriksh-9 delivered high-impact work by building core vulnerability labs including IDOR and LDAP Injection, significantly strengthening the platform’s security coverage.
@Roshan1299 contributed the Clickjacking vulnerability, adding important client-side attack scenarios to the application.

πŸ“¦ Full Changelog
πŸ‘‰ https://github.com/SasanLabs/VulnerableApp/compare/1.13...2.0.1

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track VulnerableApp

Get notified when new releases ship.

Sign up free

About VulnerableApp

All releases β†’

Beta — feedback welcome: [email protected]