-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Pull requests: OWASP/NodeGoat
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Test branch - try socket file and requirements file pull request
#419
opened May 28, 2026 by
NickStrick
Loading…
[Security Fix] SAST: NoSQL/server-side JS injection via $where with unsanitized
threshold query ...
#413
opened May 18, 2026 by
okaypatrick
Loading…
[Security Fix] SAST: User-controlled
url query parameter is fetched server-side and response bod...
#412
opened May 18, 2026 by
okaypatrick
Loading…
[Security Fix] SAST: Authenticated RCE via eval() applied to request body fields preTax/afterTax/r...
#411
opened May 18, 2026 by
okaypatrick
Loading…
fix: resolve N+1 query in allocations getByUserIdAndThreshold
#400
opened Apr 24, 2026 by
alex-vydrin
Loading…
3 tasks
Fix isAdminUserMiddleware ignoring DB errors
#399
opened Apr 24, 2026 by
alex-vydrin
Loading…
3 tasks
Fix double callback bug in allocations-dao.js
#398
opened Apr 24, 2026 by
alex-vydrin
Loading…
3 tasks
fix(security): redact secrets from config startup log (CWE-532)
#391
opened Apr 15, 2026 by
aayushbaluni
Loading…
Previous Next
ProTip!
no:milestone will show everything without a milestone.