Skip to content

VulnerableApp-2.1.0

Latest

Choose a tag to compare

@preetkaran20 preetkaran20 released this 03 Jul 01:20
668ab14

πŸŽ‰ VulnerableApp 2.1.0

A major release packed with new vulnerability modules, infrastructure hardening, and strong community growth β€” 18 new contributors joined this cycle!

πŸ›‘οΈ New Vulnerability Modules

  1. Authentication Vulnerability Module β€” full implementation, including a new "Low Iteration Password Hashing" challenge level (@ayash911, @aryankshl)
  2. Cache Poisoning β€” brand new vulnerability class added (@luks-santos)
  3. IDOR Module β€” enhanced with secure token handling (@Etoile-Bleu)
  4. Cryptographic Failures β€” module enhancements (@aashpis)
  5. Open Redirect β€” phishing-aware levels added (Levels 9, 10, 11) (@StevenTaing2, @Jhalak19-Sethi, @polcm005), plus payload/message-key improvements (@An16og)
  6. Clickjacking β€” Challenge mode support added (@Clark1945)
  7. Authentication β€” Challenge mode added (@luks-santos)

🧩 New Framework: Challenge Cards

A new @ChallengeCard annotation system was introduced for structured, gamified vulnerability challenges (@aryankshl) β€” now rolled out across multiple modules.

πŸ—οΈ Infrastructure & Tooling

  1. Docker-based dashboard added (@harveenkaur2912)
  2. Scanner benchmark framework for DAST/SAST coverage (@MukulGhare)
  3. llmforge build migrated to a Docker Hub image for easier setup (@aruzaphoenix)
  4. @Profile("public"/"unsafe") safeguards added across vulnerability controllers to separate safe/unsafe deployment modes (@prajp98)
  5. Extra scanner path configuration support (@nguyenvulong)
  6. @antriksh-9 β€” Enhanced the first-time contributor workflow
  7. @MixhizoR β€” Added secure variants to Http3xxStatusCodeBasedInjection annotations

πŸ“š Documentation & Community

  1. New organizational usage documentation added (@CharanTeja-6825)
  2. University of Adelaide added to the usage showcase (@aruzaphoenix)
  3. Design documentation grammar and formatting cleanup (@muhammadrehanazam)
  4. Facade schema population work (@saurabhkushwaha438)

πŸ“Š By the Numbers

~66 merged PRs
21 contributors
Continued momentum on infra hardening, new challenge types, and onboarding polish

Full changelog: 2.0.1...2.1.0