π VulnerableApp 2.1.0
A major release packed with new vulnerability modules, infrastructure hardening, and strong community growth β 18 new contributors joined this cycle!
π‘οΈ New Vulnerability Modules
- Authentication Vulnerability Module β full implementation, including a new "Low Iteration Password Hashing" challenge level (@ayash911, @aryankshl)
- Cache Poisoning β brand new vulnerability class added (@luks-santos)
- IDOR Module β enhanced with secure token handling (@Etoile-Bleu)
- Cryptographic Failures β module enhancements (@aashpis)
- Open Redirect β phishing-aware levels added (Levels 9, 10, 11) (@StevenTaing2, @Jhalak19-Sethi, @polcm005), plus payload/message-key improvements (@An16og)
- Clickjacking β Challenge mode support added (@Clark1945)
- Authentication β Challenge mode added (@luks-santos)
π§© New Framework: Challenge Cards
A new @ChallengeCard annotation system was introduced for structured, gamified vulnerability challenges (@aryankshl) β now rolled out across multiple modules.
ποΈ Infrastructure & Tooling
- Docker-based dashboard added (@harveenkaur2912)
- Scanner benchmark framework for DAST/SAST coverage (@MukulGhare)
- llmforge build migrated to a Docker Hub image for easier setup (@aruzaphoenix)
- @Profile("public"/"unsafe") safeguards added across vulnerability controllers to separate safe/unsafe deployment modes (@prajp98)
- Extra scanner path configuration support (@nguyenvulong)
- @antriksh-9 β Enhanced the first-time contributor workflow
- @MixhizoR β Added secure variants to Http3xxStatusCodeBasedInjection annotations
π Documentation & Community
- New organizational usage documentation added (@CharanTeja-6825)
- University of Adelaide added to the usage showcase (@aruzaphoenix)
- Design documentation grammar and formatting cleanup (@muhammadrehanazam)
- Facade schema population work (@saurabhkushwaha438)
π By the Numbers
~66 merged PRs
21 contributors
Continued momentum on infra hardening, new challenge types, and onboarding polish
Full changelog: 2.0.1...2.1.0