This is a deliberately vulnerable Node.js application created for educational purposes to demonstrate common security vulnerabilities that can be detected by GitHub CodeQL, Dependabot, and Secret Scanning.
DO NOT USE THIS CODE IN PRODUCTION. This application contains numerous security vulnerabilities and is intended solely for security training and demonstration purposes.
This application contains multiple vulnerabilities including but not limited to:
- Outdated and vulnerable dependencies
- Command injection
- SQL injection
- Cross-site scripting (XSS)
- Insecure deserialization
- Path traversal
- Weak cryptography
- Hardcoded credentials
- Insecure direct object references
- Prototype pollution
- Regular expression denial of service (ReDoS)
- Insecure random number generation
- Weak password hashing
- Insecure JWT implementation
- No rate limiting
- Insecure file operations
- Hardcoded encryption keys
- Insecure session management
- No input sanitization for database queries
- Exposing sensitive data in error messages
- Exposed API keys and secrets
- Hardcoded AWS credentials
- Private SSH keys
- OAuth client secrets
- Payment processor API keys
npm install
npm startThis application is designed to trigger alerts in:
- GitHub CodeQL
- GitHub Dependabot
- GitHub Secret Scanning
- Other security scanning tools
This application is meant to be used for:
- Security training
- Demonstrating how security scanning tools work
- Learning about common web application vulnerabilities
- Understanding secure coding practices (by seeing what NOT to do)
- Showing how secret scanning tools detect exposed credentials