-
Notifications
You must be signed in to change notification settings - Fork 101
AI entries revised #464
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
AI entries revised #464
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Adding: P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure P1 - AI Application Security - Remote Code Execution - Full System Compromise P1 - AI Application Security - Sensitive Information Disclosure - Key Leak P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution P2 - AI Application Security - Prompt Injection - System Prompt Leakage P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS) P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes P5 - AI Application Security - Improper Input Handling - Unicode Confusables P5 - AI Application Security - Improper Input Handling - RTL Overrides
RRudder
added a commit
to bugcrowd/templates
that referenced
this pull request
Jun 2, 2025
These updates are to match the VRT update - bugcrowd/vulnerability-rating-taxonomy#464 Adding: P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure . P1 - AI Application Security - Sensitive Information Disclosure - Key Leak P1 - AI Application Security - Remote Code Execution - Full System Compromise P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution P2 - AI Application Security - Prompt Injection - System Prompt Leakage P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS) P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes P5 - AI Application Security - Improper Input Handling - Unicode Confusables P5 - AI Application Security - Improper Input Handling - RTL Overrides Removing: P1 - AI Application Security - Large Language Model (LLM) Security - LLM Output Handling P1 - AI Application Security - Large Language Model (LLM) Security - Prompt Injection P1 - AI Application Security - Large Language Model (LLM) Security - Training Data Poisoning P2 - AI Application Security - Large Language Model (LLM) Security - Excessive Agency/Permission Manipulation
nnons
pushed a commit
that referenced
this pull request
Jun 20, 2025
* GraphQL Introspection Enabled - P5 #450 * Bypass of Password Confirmation on Password Change Add: Broken Access Control – Bypass of Password Confirmation – Change Password * Revert "Bypass of Password Confirmation on Password Change" This reverts commit a6e415a. * Bypass of Password Confirmation on Password Change Add: Broken Access Control – Bypass of Password Confirmation – Change Password * Revert "Bypass of Password Confirmation on Password Change" This reverts commit 3418212. * Broken Access Control (BAC) - Bypass of Password Confirmation - Change Password (#462) * Revert "Bypass of Password Confirmation on Password Change" This reverts commit 3418212. * Bypass of Password Confirmation on Password Change Add: Broken Access Control – Bypass of Password Confirmation – Change Password * AI entries revised (#464) * AI entries revised Adding: P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure P1 - AI Application Security - Remote Code Execution - Full System Compromise P1 - AI Application Security - Sensitive Information Disclosure - Key Leak P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution P2 - AI Application Security - Prompt Injection - System Prompt Leakage P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS) P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes P5 - AI Application Security - Improper Input Handling - Unicode Confusables P5 - AI Application Security - Improper Input Handling - RTL Overrides * Update vulnerability-rating-taxonomy.json * Fixing errors * Fixing errors2 * Update vulnerability-rating-taxonomy.json * Update vulnerability-rating-taxonomy.json * Update vulnerability-rating-taxonomy.json * Update vulnerability-rating-taxonomy.json * Update vulnerability-rating-taxonomy.json * Update cvss_v3.json * Fixed deprecated node mapping (#457) * Updated varies to default and removed redundant entries (#461) * Updated varies to default and removed redundant entries * Reverting some changes --------- Co-authored-by: Abhinav Nain <abhinav.nain@bugcrowd.com> * Final Changes - Adding Changelog + deprecated-node-mappings + ALL JSON Sorting + SCW --------- Co-authored-by: SamAtBugcrowd <100110742+SamAtBugcrowd@users.noreply.github.com> Co-authored-by: Abhinav Nain <abhinav.nain@bugcrowd.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Adding:
P1 - AI Application Security - Training Data Poisoning - Backdoor Injection / Bias Manipulation
P1 - AI Application Security - Model Extraction - API Query-Based Model Reconstruction
P1 - AI Application Security - Sensitive Information Disclosure - Cross-Tenant PII Leakage/Exposure .
P1 - AI Application Security - Sensitive Information Disclosure - Key Leak
P1 - AI Application Security - Remote Code Execution - Full System Compromise
P2 - AI Application Security - Remote Code Execution - Sandboxed Container Code Execution
P2 - AI Application Security - Prompt Injection - System Prompt Leakage
P2 - AI Application Security - Vector and Embedding Weaknesses - Embedding Exfiltration / Model Extraction
P3 - AI Application Security - Vector and Embedding Weaknesses - Semantic Indexing
P2 - AI Application Security - Denial-of-Service (DoS) - Application-Wide
P4 - AI Application Security - AI Safety - Misinformation / Wrong Factual Data
P4 - AI Application Security - Insufficient Rate Limiting - Query Flooding / API Token Abuse
P4 - AI Application Security - Denial-of-Service (DoS) - Tenant-Scoped
P4 - AI Application Security - Adversarial Example Injection - AI Misclassification Attacks
P3 - AI Application Security - Improper Output Handling - Cross-Site Scripting (XSS)
P4 - AI Application Security - Improper Output Handling - Markdown/HTML Injection
P5 - AI Application Security - Improper Input Handling - ANSI Escape Codes
P5 - AI Application Security - Improper Input Handling - Unicode Confusables
P5 - AI Application Security - Improper Input Handling - RTL Overrides
Removing:
P1 - AI Application Security - Large Language Model (LLM) Security - LLM Output Handling
P1 - AI Application Security - Large Language Model (LLM) Security - Prompt Injection
P1 - AI Application Security - Large Language Model (LLM) Security - Training Data Poisoning
P2 - AI Application Security - Large Language Model (LLM) Security - Excessive Agency/Permission Manipulation