VulnAPI

VulnAPI

**Vulnapi** is a ** API application ** that is deliberately designed to be extremely insecure ** and deliberately contains a lot of poor programming practices.

Description

**Vulnapi** is a ** API application ** that is deliberately designed to be extremely insecure ** and deliberately contains a lot of poor programming practices. The main purpose of this project is to demonstrate various security vulnerabilities and erroneous practices in Python3 coding and operations (such as Docker), and is also suitable as a demonstration and testing platform for DevSecOps methods. Default account: luke / tatooine ###Main characteristics - ** Rich security vulnerabilities **: There are many common and serious security vulnerabilities built in, including: - Data breach (by triggering logic issues) - Mass Assignment Vulnerability - Missing object-level permission control - Defects in certification mechanism - Remote code execution (RCE) caused by deserialization - SQL injection - File inclusion and path traversal - ** Poor code practices **: The project code is deliberately written in a way that is not recommended to facilitate security testing and demonstration. - ** Suitable for security demonstrations/training **: Suitable for vulnerability mining, attack and defense drills, security automation testing and other scenarios.

Screenshots
Screenshot 1
Screenshot 2
Mobile Screenshots
Mobile Screenshot 1
Mobile Screenshot 2
Mobile Screenshot 3
App Information
Version
0.1.1
Package Size
18.49 KB
Image Size
179.17 MB
Updated
October 11, 2025
Source Code
vulnerable-apps
Platform Support
PCMobile
Keywords
safe shooting range
VulnAPI | SelfHost