How AigentX autonomously mapped the OWASP crAPI API, tested 47 endpoints, validated 37 findings and built 7 attack chains, without source code, credentials or API documentation.
47endpoints
37validated findings
7attack chains
rootaccess achieved
Conditions
No source. No credentials supplied. No API specification.
The test reproduced the starting point of an external attacker meeting an unfamiliar application.
Assessed
July 2026
Target
OWASP crAPI, deployed and operated by KomodoSec as an authorized lab
Input
Public application URL only
Access
Self-registration: a regular account created through the public flow
Documentation
None provided. No Swagger, OpenAPI, endpoint inventory or architecture docs
Code visibility
Black box. No source or repository access
Test design
No predefined test cases. The agent chose its own strategy
Method
From zero documentation to the complete API surface.
Coverage required understanding how the application works, not collecting paths and sending generic payloads.
01
Discover entry points
Identify registration, login, browser calls and service boundaries.
02
Create valid state
Register a user, authenticate and preserve tokens, identifiers and application objects.
03
Follow business flows
Upload media, create vehicle relationships, place orders and exercise community workflows.
04
Map the API
Enumerate 47 endpoints distributed across 4 microservices.
05
Test every endpoint
Apply context-aware authentication, authorization, injection and logic tests.
06
Chain confirmed weaknesses
Use outputs from one workflow as inputs to the next attack step.
Primary chain
A regular user became root.
The highest-impact result depended on carrying state across services and combining three behaviors that were less severe separately.
01
Self-register
Obtained legitimate ROLE_USER access.
02
Create state
Uploaded media to produce the video_id the next step required.
03
Inject
Placed shell metacharacters in conversion_params.
04
Pivot
Reached the internal convert_video endpoint via SSRF from a separate service.
05
Execute
Received command output from the identity container as root.
06
Extract
Recovered JWT_SECRET, DB_PASSWORD and TLS key material.
Proven impact.uid=0(root) command execution on crapi-identity, followed by extraction of DB_PASSWORD, JWT_SECRET and TLS keystore credentials.
7 paths from isolated weaknesses to business impact.
The chains show why correlation matters: the impact of one issue often depends on what another makes reachable.
Chain
Outcome
Composition
Risk
AC-01
Root compromise
SSRF + command injection
Critical
AC-02
Zero-credential account takeover
Public MailHog + OTP weakness
Critical
AC-03
Permanent account takeover
Unsigned JWT + password reset
Critical
AC-04
Authenticated account takeover
SSRF + OTP interception
High
AC-05
Unlimited credit generation
Coupon + order logic abuse
High
AC-06
Unauthenticated PII enumeration
VIN disclosure + BOLA
High
AC-07
Fraudulent work orders
Directory exposure + BFLA
Medium
Severity distribution of 37 validated findings
Severity
Findings
Critical
4
High
19
Medium
8
Low
5
Informational
1
Critical4
High19
Medium8
Low5
Informational1
37 validated findings.
Expand any finding with recorded evidence to see the requests and responses behind it. Every finding was reproduced against the live lab during review.
F016HighBOLA Exposes Vehicle GPS Location and Owner PII
F017HighBOLA/IDOR in Change-Email Enables Account Takeover
F018HighBOLA + BFLA Allows Reading Any Mechanic Report
F019HighBOLA Exposes Merchant Service History for Any VIN
F020HighNo Rate Limiting on Vehicle Pincode
Proof of exploit, F021
POST /workshop/api/shop/apply_coupon
{"coupon_code":"TRAC075","amount":500}
-> {"credit":600.0,"message":"Coupon successfully applied!"}
POST /workshop/api/shop/orders
{"product_id":1,"quantity":-1}
-> {"message":"Order sent successfully.","credit":610.0}
F022HighNegative Quantity Order Generates Unlimited Credit
CWE-943 — Improper Neutralization of Special Elements in Data Query Logic
Proof of exploit, F023, block 1 of 2
POST /community/api/v2/coupon/validate-coupon HTTP/1.1
Host: aigentx-lab.komodosec.com
Authorization: Bearer <JWT>
Content-Type: application/json
{}
HTTP/1.1 200 OK
Content-Type: application/json
{"coupon_code":"TRAC075","amount":10}
Proof of exploit, F023, block 2 of 2
POST /community/api/v2/coupon/validate-coupon HTTP/1.1
Host: aigentx-lab.komodosec.com
Authorization: Bearer <JWT>
Content-Type: application/json
{"coupon_code":{"$ne":null}}
HTTP/1.1 200 OK
Content-Type: application/json
{"coupon_code":"TRAC075","amount":10}
F024MediumDeprecated Login-With-Token Endpoint Remains Active
F025MediumNo Login Lockout or Rate Limiting
F026MediumNo Rate Limiting on User Registration
F027MediumBFLA Allows Users to Create Mechanic Requests for Any Vehicle
F028MediumMechanic Directory Exposed to All Authenticated Users
F029MediumGlobal Coupon Codes Reusable Across Accounts
F030LowMissing Server-Side Sanitization on Community Comments
F031LowUnvalidated redirect_url in Password Reset
F032LowUser Enumeration via Distinct Error Messages
F033LowCORS Wildcard Across Multiple Services
F034LowMissing and Misconfigured Security Headers
F035InformationalChatbot State Accessible Without Authentication
F036HighNo Rate Limiting on Phone OTP Verification
F037MediumNo Rate Limiting on Forget-Password OTP Trigger
AigentX tests applications as systems, not collections of URLs.
Automated scanners test known signatures against known paths. AigentX explores how the application works, identifies what each workflow makes possible and continues until the real attack path is understood.
OWASP crAPI is an intentionally vulnerable open-source application designed for API security training. This assessment ran against KomodoSec's authorized lab deployment. The value demonstrated is not that crAPI contains vulnerabilities, but that AigentX discovered the surface and validated the set without source code, credentials or API documentation.