Skip to content

v3.7.26-beta

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 30 Jul 22:06
· 25 commits to main since this release

Highlights

  • JWT head-start: the JWT specialist gets a bounded head-start before the rest of the specialist pool, so a cracked admin token is available to auth-dependent specialists from the start of exploitation instead of arriving mid-run.
  • IDOR accuracy: differential analysis now gates length/sensitive-data indicators on a successful (200) test response, fixing a false-confirm on 404 edge-case IDs that could stop candidate testing before reaching the real vulnerable ID.
  • Reporting accuracy: nuclei-sourced request/response evidence now reaches the PoC and CVSS enrichment prompts. A confirmed file-disclosure finding (e.g. local file inclusion) can no longer be downgraded to "not demonstrated" by the generic-probe guardrail when real evidence exists.
  • Deterministic Nuclei scanning: added a fixed-tag scan phase as a guaranteed floor before the opportunistic auto-scan phase, fixing run-to-run finding variance against an unchanged target. A Nuclei subprocess failure no longer takes down independent app-level checks (headers/cookies/GraphQL/rate-limiting).
  • Provider defaults: updated off a deprecated upstream model in the default OpenRouter preset.

Validation

Validated against BugStore (71.4% detectable recall via the project's benchmark scorer), ginandjuice.shop, and a live third-party target — clean runs, no regressions.