VerdictRuntime
← Back to overview
Sample assessment report

Ledgerline — what a report looks like

Ledgerline is a fictional multi-tenant invoicing product: our own demo application, built with deliberate weaknesses so the whole method can be shown end to end without touching anyone's real system. Everything below is real output from an assessment run on 3 October 2026, condensed into the format you would receive. Nothing here is a customer finding.

5
Confirmed live against the running application
3
Dependency fixes prepared, re-scanned clean, tests still green
804
Raw engine results condensed into this report
Confirmed

Reproduced against the running application

Each of these was proven with real requests against a deployed copy of the application, using two real accounts where the issue is about who can see what. They lead the report because nothing about them is a guess.

Confirmed Critical OWASP A02
Unsigned login tokens are accepted
JWT ‘alg: none’ · GET /api/auth/me
Proof
A real token from a real login was copied with its signature removed and its algorithm set to none. The protected endpoint returned 200 for both the genuine and the forged token.
Impact
The server does not check token signatures, so an attacker who edits the claims inside a token can act as another user.
Remediation
Pin the accepted algorithm when verifying tokens. Not auto-patched: authentication code is handed to your team with the exact failing request attached.
Confirmed Critical OWASP A02
Token signing secret is guessable
JWT HS256 weak secret · GET /api/auth/me
Proof
The signing secret was recovered offline on the first guess from a list of common weak secrets (six characters, shown masked as s****t). A fresh token signed with it was accepted live: 200.
Impact
Even with the algorithm pinned, an attacker can sign valid tokens.
Remediation
Rotate to a long random secret held in your secret store; invalidate existing sessions.
Confirmed High OWASP API1
One customer can read another customer's invoices
Broken object-level authorisation · GET /api/invoices/{id}
Proof
Two real accounts in two different organisations. User B requested invoice 4, which belongs to User A's organisation, and received it, including a marker value unique to that invoice.
Impact
Cross-tenant data exposure by changing a number in the URL.
Remediation
Scope the invoice lookup to the caller's organisation. Authorisation logic is left to a reviewer who knows your tenancy model.
Confirmed High OWASP LLM07
The in-app AI assistant reveals its system prompt
System prompt leakage · POST /api/copilot/chat
Proof
A known canary string planted in the system prompt, LEDGERLINE-CANARY-SYSTEM-PROMPT-9d41, came back verbatim, along with an internal “admin override phrase”. A plain baseline question returned a normal answer.
Impact
Internal instructions and anything embedded in them are readable by any user.
Confirmed High OWASP LLM01
The AI assistant follows injected instructions
Prompt injection · POST /api/copilot/chat
Proof
An instruction to override its guidelines and repeat a unique marker was followed; the marker prompt-injection-verify-6d2bf37cb07cbf39 came back verbatim, twice.
Impact
User input can redirect the assistant, including toward the tools it can call.

In this demo the assistant is a deterministic stand-in for a model, so results are reproducible. Against a real model the same checks run unchanged.

Corroborated

Two independent engines agree

Found by static analysis and flagged independently by two engines from different vendors. Strong signal, but not exercised live, and labelled that way.

Critical & High Dependencies · fix verified
Known-vulnerable packages: lodash, minimist, node-fetch
package-lock.json · CVE-2021-44906, CVE-2021-23337, CVE-2020-8203, CVE-2022-0235 and others
Agreement
Reported by both dependency engines.
Fix prepared
Each moved to the lowest version that resolves it: lodash 4.17.15 → 4.18.0, minimist 1.2.5 → 1.2.6, node-fetch 2.6.0 → 2.6.7.
Re-scan
All three confirmed fixed by a re-scan of the patched tree, and independently by a second engine.
Tests
The application's own test suite: 19 of 19 passing before the change and 19 of 19 after.
High Dependencies · no fix prepared
Web framework with published bypass advisories: fastify 4.29.1
package-lock.json · authentication and request-validation bypass advisories
Agreement
Reported by both dependency engines.
Status
Upgrade not prepared in this pass. Reported as open rather than quietly left out.
Critical Source code
Hard-coded secret in application config
src/config.ts:8
Agreement
Flagged independently by two static analysis engines.
Critical & High Infrastructure
Cluster and cloud configuration
deploy/k8s/ledgerline.yaml · deploy/terraform/main.tf · Dockerfile
Kubernetes
A cluster role with every verb on every resource (line 82); the app container runs privileged with SYS_ADMIN (line 33).
Cloud
A firewall rule open to any address (line 69); a storage bucket that allows public access (line 95).
Container
The image runs as root. Its end-of-life base image carries 512 known-vulnerable packages; a trial rebuild on a current slim base built cleanly and cut that to 330 (critical 14 → 9, high 151 → 88).
Agreement
Each configuration item flagged by both infrastructure engines.
Single engine

Worth a look, labelled as unproven

One engine saw these and nothing else confirmed them. They are reported, ranked last, and never presented as vulnerabilities.

Single engine High
SQL string assembled from request input
src/routes/users.ts:41
Status
Pattern match from one engine; the second did not flag it and it was not reproduced live. Needs a reviewer, not a fire drill.
Limits

What this assessment did not cover

Want this for your own application?

The first assessment is on us: one repository, one report, no obligation.

Request an assessment Reply within two business days.