Repository navigation
v3.7.17-beta
Fixes
Scanning with Anthropic or Z.ai works again. The pre-scan diagnostics gate read
OPENROUTER_API_KEY unconditionally, so a fully configured scan aborted with
"Diagnostics failed" while /health reported the key as present. The gate now reads the
ACTIVE provider preset, and the connectivity probe targets that provider's host.
Vision validation uses a model the active provider actually serves, instead of a slug
that returns 404 and silently disables visual proof.
Reports are viewable again. Finding.cvss_score was declared as a string while the
pipeline computes a number, so every report carrying a score failed validation and the
html/json/markdown endpoints returned 404.
Proof screenshots show the banner. The visual PoC payload contained literal spaces, so
in an unquoted attribute context the browser cut it at the first space and threw
"Unexpected end of input" — the screenshot never showed impact. The banner is now
whitespace-free.
Payloads survive the report. The narrative's quoted payload is fenced after the visual
upgrade, so it reaches the reader byte-exact instead of losing its backticks to the
markdown renderer. Report URLs keep gospider's FUZZ placeholder verbatim rather than
being rewritten into a URL that was never sent. sqlmap evidence keeps the verdict block
instead of the ASCII banner, which also restores DBMS detection.
Template injection. The CSTI prompt asked the model to prove with {{7*7}} while the
confirmation step only accepts 1000003*1000003 → 1000006000009, so its payloads could
never be accepted. Prompt and predicate now agree.
Known limitations
sqlmap boolean-based cookie SQLi can still report false CRITICALs; the XSS ladder can
still confirm on reflection contexts that cannot execute (<title>, <meta>); GoSpider's
read timeout can truncate recon without saying so.