Engagement: meridian-prod
Meridian Systems · SaaS · week 7 of continuous coverage · scope: 6 surfaces, 214 assets
plan Continuous · unlimited runs env production last sync 2026-08-08 14:37 UTC Fleet live
Critical open
2
1 chain proven · both paged
High open
7
3 with fixes in review
Gaps closed
4today
148 all-time · retest-verified
Mean time-to-proof
41min
first request → captured proof
Surfaces covered
6/ 6
web · API · cloud · auth · secrets · AI
Agents active now
5
across 5 targets · 0 out-of-scope halts

Open findings by severity

46 open

Found vs. fixed

14-day trend
Found Fixed & verified
241found · 14 days
263fixed · 14 days
−22net backlog change

Proven attack path

CRITICAL
1
Recon
undocumented /internal/* found
2
Exposed API
GET /internal/metrics — no auth
3
Leaked token
CI deploy token in response header
4
Assumed role
sts:AssumeRole → prod-deploy
5
Customer data
1.24M records reachable
CVSS 9.6CRITICAL
47 minto proof
1.24Mrecords in blast radius

Halted at COUNT(*) — no records read. Fix opened as PR #2291 · in review.

Attack surface coverage

tested reachable surface · 46 open findings
Web applications96%
authz · business logic · workflow11 findings
APIs & GraphQL92%
object-level authz · mass assignment13 findings
Cloud estate88%
roles · storage · lateral movement8 findings
Identity & SSO90%
SAML · session · tenant isolation6 findings
CI/CD & secrets84%
pipeline perms · leaked tokens5 findings
AI / LLM interfaces71%
prompt injection · tool-call abuse3 findings

Agents running now

live · 5 active
mapper-02
api.meridian.io
enumerating GraphQL schema · 214 types
Map
reasoner-04
app.meridian.io
modelling checkout & refund flow
Reason
exploiter-01
auth.meridian.io
testing SAML response signature
Exploit
chainer-03
aws · prod-account
walking role-assumption graph
Chain
prover-02
llm-gw.meridian.io
capturing injection PoC (safe)
Prove

Newest findings

exploit-validated only
CRIT
Leaked CI token in build log grants prod role assumption
CI/CD & secrets · run #9014
22m
HIGH
IDOR on /api/v2/invoices exposes cross-tenant records
APIs & GraphQL · run #9012
1h
HIGH
SAML response signature not validated on login
Identity & SSO · run #9011
2h
MED
Prompt injection exfiltrates system prompt via tool call
AI / LLM · run #9009
3h
MED
Over-permissive S3 policy on nightly backup bucket
Cloud estate · run #9007
5h
LOW
Verbose error leaks stack trace on /api/health
APIs & GraphQL · run #9005
6h
LOW
Missing rate limit on /password-reset
Identity & SSO · run #9003
8h