Super vulnerable todo list application
JavaScript CSS HTML Shell
Latest commit e24671d Nov 28, 2016 @guypod guypod committed on GitHub Merge pull request #24 from guypod/master
chore: add heroku file, configurable goof host

Goof - Snyk's vulnerable demo app

Known Vulnerabilities

A vulnerable Node.js demo application, based on the Dreamers Lab tutorial.


mongod &

git clone
npm install
npm start


To bulk delete the current list of TODO items from the DB run:

npm run cleanup

Exploiting the vulnerabilities

This app uses npm dependencies holding known vulnerabilities.

Here are the exploitable vulnerable packages:

The exploits directory includes a series of steps to demonstrate each one.

Fixing the issues

To find these flaws in this application (and in your own apps), run:

npm install -g snyk
snyk wizard

In this application, the default snyk wizard answers will fix all the issues. When the wizard is done, restart the application and run the exploits again to confirm they are fixed.