Critical open
2
1 chain proven · both paged
High open
7
3 with fixes in review
Gaps closed
4today
148 all-time · retest-verified
Mean time-to-proof
41min
first request → captured proof
Surfaces covered
6/ 6
web · API · cloud · auth · secrets · AI
Agents active now
5
across 5 targets · 0 out-of-scope halts
Open findings by severity
46 openFound vs. fixed
14-day trend
Found
Fixed & verified
241found · 14 days
263fixed · 14 days
−22net backlog change
Proven attack path
CRITICAL1
Recon
undocumented /internal/* found
2
Exposed API
GET /internal/metrics — no auth
3
Leaked token
CI deploy token in response header
4
Assumed role
sts:AssumeRole → prod-deploy
5
Customer data
1.24M records reachable
CVSS 9.6CRITICAL
47 minto proof
1.24Mrecords in blast radius
Halted at COUNT(*) — no records read. Fix opened as
PR #2291 · in review.
Attack surface coverage
tested reachable surface · 46 open findings
Web applications96%
APIs & GraphQL92%
Cloud estate88%
Identity & SSO90%
CI/CD & secrets84%
AI / LLM interfaces71%
Agents running now
live · 5 active
mapper-02
Map
api.meridian.io
enumerating GraphQL schema · 214 types
reasoner-04
Reason
app.meridian.io
modelling checkout & refund flow
exploiter-01
Exploit
auth.meridian.io
testing SAML response signature
chainer-03
Chain
aws · prod-account
walking role-assumption graph
prover-02
Prove
llm-gw.meridian.io
capturing injection PoC (safe)
Newest findings
exploit-validated onlyCRIT22m
Leaked CI token in build log grants prod role assumption
CI/CD & secrets · run #9014
HIGH1h
IDOR on /api/v2/invoices exposes cross-tenant records
APIs & GraphQL · run #9012
HIGH2h
SAML response signature not validated on login
Identity & SSO · run #9011
MED3h
Prompt injection exfiltrates system prompt via tool call
AI / LLM · run #9009
MED5h
Over-permissive S3 policy on nightly backup bucket
Cloud estate · run #9007
LOW6h
Verbose error leaks stack trace on /api/health
APIs & GraphQL · run #9005
LOW8h
Missing rate limit on /password-reset
Identity & SSO · run #9003
Past weekly reports