Files
NeuroSploit/neurosploit-rs
CyberSecurityUPandClaude Opus 5 6475dba752 feat(validation): 13 more CWE validators, each with a rejection rule
Six classes had deterministic rules; the rest of a run still rested on models
voting. These thirteen cover the classes that produce the most false positives
in AI-driven testing, and each one is written around what *disproves* the
claim, because that is the part a language model skips:

  SSTI          an expression evaluated server-side whose result was never
                sent — the payload echoing its own "result" is rejected
  XXE           entity content or an OOB callback; a parser error mentioning
                entities shows the DTD was read, not that anything resolved
  Open redirect 3xx WITH a Location off-site; a rendered link is not a redirect
  CORS          reflected Origin PLUS credentials; ACAO:* without credentials
                exposes only what an anonymous client could already read, and
                ACAO:* WITH credentials is refused by browsers anyway
  Cookie flags  fully decidable from Set-Cookie + scheme
  Clickjacking  neither X-Frame-Options nor CSP frame-ancestors
  Auth bypass   protected content with NO credentials sent — a "bypass" whose
                request still carried a cookie is rejected, as is a redirect
                to login
  JWT           forged token accepted AND privileged content returned
  Rate limiting >= 20 attempts with no 429/Retry-After; five attempts prove
                nothing about a limit that was never reached
  Session fix.  the session id surviving login unchanged
  Mass assign.  a read-back proving the field persisted — a 200 on the write
                means nothing, APIs accept and ignore extra fields routinely
  CSRF          a cross-origin state change read back; a SameSite session
                cookie means a browser would never attach it cross-site
  Exposure      a real secret/listing signature the baseline lacked; a
                soft-404 mirroring the baseline page is rejected

Exchange gains response and request headers, because several of these classes
are decided by a header (Location, Set-Cookie, Access-Control-Allow-*) and the
body alone is not evidence for them.

A test asserts no two validators claim the same CWE — ambiguous ownership would
make routing depend on registration order, which is how a class silently gets
the wrong rule.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-13 15:10:23 -03:00
..