flagnone

urn:signet:att:sha256:6a77eedf06cc5544d47fdb598e72f73f2067e0c8b5791ef33690e9c86e2d324d

signed by sha256:dfa4d8db59a4d6315c6e7… (tier 0) · registered 2026-07-20T07:49:08.775071Z

Subjects

  • https://github.com/expressjs/express @ f60718293a4b5c6d7e8f90123456789012345678

Flag

reason: incorrect

alleged class: CWE-89

evidence: PoC: nested query object bypasses the sanitizer

against: urn:signet:att:sha256:722f8c48d561aa2d23e316

Verifications (0)

none yet

Raw statement (decoded payload)
{
  "_type": "https://in-toto.io/Statement/v1",
  "predicate": {
    "attestation": "urn:signet:att:sha256:722f8c48d561aa2d23e316d7e2e6b810ca4ad75005e7d53f7a7982f52bab86a7",
    "evidence": "PoC: nested query object bypasses the sanitizer",
    "reason": "incorrect",
    "schemaVersion": "1.0.0",
    "timestamp": "2026-07-19T21:00:00Z",
    "vulnClass": "CWE-89"
  },
  "predicateType": "https://signet.dev/attestation/flag/v1",
  "subject": [
    {
      "digest": {
        "gitCommit": "f60718293a4b5c6d7e8f90123456789012345678"
      },
      "name": "https://github.com/expressjs/express"
    }
  ]
}