This website uses cookies

Read our Privacy policy and Terms of use for more information.

Bayou Bytes  //  Issue #13 · Nobody Asked It

Come, Take Your First Byte.

Three sections, twelve minutes. Starting now.
 
New free tool drops today
Gatorbyte #015 — free download, one afternoon per app
The Vibe-Coded App Pre-Launch Kit →

The Pulse

Every Tuesday: the threats that actually moved, one fix you can ship before lunch, and the plain-English version your non-technical CEO needs to hear. Three things worth your scroll this week — all three read off CISA’s Known Exploited Vulnerabilities catalog, version 2026.09.24, in professionally built products: two are authentication or authorization checks the server got wrong; the third is a path traversal in an API gateway.

Now, this week:

🔴 Threat level: elevated — and two of this week’s three are trust checks the server got wrong.

1 · An online store platform decided who could see what — incorrectly. On Sep 24 CISA added CVE-2026-71362 in Adobe Commerce and Magento to the catalog, filed under CWE-863, Incorrect Authorization. CISA’s entry describes a flaw that could let an attacker gain elevated access to sensitive resources without any user interaction. Remediation date: Sep 27 — three days, binding on federal civilian agencies only, free for everyone else to copy as a signal. Adobe’s bulletin is APSB26-92. If you host a storefront for a client, that is the one to read first.

→ helpx.adobe.com · APSB26-92

2 · An AI gateway accepted a Bearer token it should have checked. Earlier this month (added Sep 2) the catalog took CVE-2026-59822 in BerriAI LiteLLM — CWE-287 / CWE-306. Per CISA’s entry, the flaw sits in LiteLLM’s MCP Streamable HTTP endpoint and could let an unauthenticated attacker establish an authenticated MCP session using an arbitrary Bearer token. Federal remediation date was Sep 16 (fourteen days, federal civilian agencies only). If a team you support stood up an AI gateway this year, confirm its version against the project’s advisory GHSA-7488-6r32-c95q.

→ github.com/BerriAI/litellm · GHSA-7488-6r32-c95q

3 · The API gateway’s file path was not the boundary it looked like. Also on Sep 24: CVE-2026-5430, a path traversal across WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway. CISA’s entry says it could allow unrestricted file upload and lead to remote code execution. Remediation date Sep 27 for federal civilian agencies only. WSO2’s advisory is WSO2-2026-5328.

→ cisa.gov/known-exploited-vulnerabilities-catalog

 

The Hardened Stack

Deep Dive: the AI made it work. Nobody asked it to make it safe.

Somebody on your side of the table shipped an app this quarter that no security person ever read — a client intake portal, a technician’s internal tool, a dashboard built in an afternoon with an AI coding assistant. It works. That is not the question any more.

The measurement. Veracode’s 2026 GenAI Code Security Report (Jul 28) tracks code from more than 100 models. By Veracode’s numbers, it compiles at a near-universal ~100% syntax pass rate — and passes Veracode’s security tests 56% of the time on average, “virtually unchanged” from its previous report. Two conditions ride with that number: no security-specific prompting, and raw models — not agents, not tools with guardrails, not code a human reviewed. Veracode’s best performer that round still failed nearly one security task in three. Read it for what it is: not “AI code is bad”, but “unreviewed code is unreviewed”.

The shape, twice. In March 2025 a researcher at Replit (Matt Palmer — worth knowing Replit builds a competing AI app builder) and a colleague scanned 1,645 apps from Lovable’s own “Launched” showcase. Visiting homepages only, never logging in, their script found 170 projects (~10.3%) with 303 endpoints that would return data with inadequate Row Level Security — emails, phone numbers, payment details, developer API keys. It was published as CVE-2025-48757 in May 2025. Homepages only means that count is a floor, not a ceiling (our read).

In January 2026, Wiz researchers browsed Moltbook — a viral social network for AI agents whose founder said publicly he vibe-coded it — and within minutes found a Supabase key in the site’s client-side JavaScript. Wiz is careful here, and so are we: that was a publishable key, meant to sit in a browser. The missing piece was the server-side Row Level Security rule that makes it safe. Without it, per Wiz, the key gave unauthenticated read and write access: 1.5 million API authentication tokens, 35,000 email addresses, private messages between agents, and the ability to edit live posts. Moltbook secured it within hours of Wiz’s report. Wiz’s own summary: the issue traced back to a single Supabase configuration setting. This was a research disclosure, not an attack report. (Per Wiz, researcher Jameson O’Reilly independently found the same misconfiguration.)

Why it keeps happening. OWASP’s Top 10:2025 keeps Broken Access Control at #1, and says access control is only effective in trusted server-side code. Its own example is an app that keeps its access checks in the front end; the attacker skips the page and calls the admin URL directly. The button is hidden. The route is not. An assistant builds what was asked for — a form, a session, a redirect — and the controls that only matter under attack were never in the request.

THE PRE-LAUNCH AFTERNOON — ONE APP

1  PICK     one app a real person can sign into.
            Not the portfolio. This one.
2  SECRETS  search the BUILT front end (view
            source, network tab, build output),
            not the repo, for keys. Publishable
            key: fine. Service / admin key: remove,
            redeploy, rotate, treat as exposed.
3  ROWS     for every table the browser can
            reach, confirm the row rule EXISTS
            — then prove it WORKS: two test
            accounts, B's record as A and with no
            session; read AND write. Expect nothing.
4  ROUTES   call the admin endpoints directly as
            an ordinary user. Expect a refusal
            or an empty result, never the data.
5  HOW      every PASS gets a How-verified line.
            "The assistant said it did" is not
            a how. Date it. Name an owner.

Step 3 is the one both case studies turn on, and a policy-existence scanner cannot prove it for you: a rule that exists is not a rule that works. Palmer’s write-up (May 2025) says Lovable’s later scanner checked that a policy existed, not whether it was correct — his assessment, and the lesson holds either way. Test from the outside, as someone who should not get in.

And run it only on apps you own or are authorized to test. The same afternoon aimed at someone else’s app is a different conversation entirely.

GB015: 26 controls · the login-page five · the how-verified register →

⚠️ Test only systems you own or are authorized to test. If a check turns up data that should not have been readable, treat it as a potential exposure: follow your incident-response plan and engage counsel and your insurer per its terms — notification duties are a legal question, not a checklist one. The kit supports secure-development, pre-release review and audit-preparation workflows — a practical starting point to review and adapt for your organization; not legal, compliance, or audit advice, and not a substitute for a penetration test or an application security assessment.

 

The Boardroom Bridge

Reviewing the app without killing the project

The talking point (a literal script for non-technical execs — steal it)

“The team built something useful fast, and I am not asking to slow it down. I am asking for one afternoon before a real customer signs in. In Veracode’s 2026 testing, code from AI models compiles almost every time and passes security checks only about half the time when nobody asks it about security — raw models, no review. Two widely reported exposures of AI-built apps, one in 2025 and one this year, came down to the same missing rule behind a public key. I want a named person to check that rule and the rest of a twenty-six-point list, write down how each one was verified, and hand you a dated page. Best case it comes back clean and we have the record. The alternative is finding out from a stranger.”

Boards do not fund fear. They fund an afternoon that ends in a one-page dated record either way it lands — and “we reviewed it before launch, here is the page” is an easier sentence to say to a client than any of the alternatives.

 
The Security Gator  //  Quick Poll
30 Seconds
Before an app built with an AI assistant goes live at your shop (or a client’s), who actually reviews it?

Pick the honest one, not the aspirational one. Answers shape the next round of playbooks — anonymous, aggregated, no list-building tricks.

○  A security person, every time ○  Whoever built it ○  We ask the assistant to review itself ○  Honestly? Nobody yet
Tap your answer → one quick confirm → counted.
● Anonymous · aggregated   —   thesecuritygator.com
Next week’s Reader Q&A answers the winning option.
 

This week’s tool — AxiomLens

The afternoon gives you one dated page for one app. Keeping that true across every app and every client — tying each finding to the control it evidences, tracking the fix, and turning it into something a board reads without translation — is the grind. That rhythm is what AxiomLens systemizes: 106 subcategories, computed coverage, evidence tied to controls, board reports written on your machine. One-time, per named user, and nothing phones home after activation. It supports compliance documentation and audit-prep workflows; a tool, not a certification, and not legal, compliance, or audit advice.

One-time license — check the store for current pricing.

Watch the walkthrough → youtu.be/namYnNbox4k
Sources: Veracode 2026 GenAI Code Security Report (release, Jul 28, 2026)  |  Matt Palmer — Statement on CVE-2025-48757 (May 29, 2025)  |  Wiz — Hacking Moltbook (Feb 2, 2026)  |  OWASP Top 10:2025 — A01 Broken Access Control  |  CISA KEV JSON feed (read 2026-09-25, catalogVersion 2026.09.24)
Every figure names its publisher. KEV remediation dates bind federal civilian agencies only. The Security Gator is not affiliated with Veracode, Wiz, OWASP, Replit, Lovable or Moltbook.
 
THE SECURITY GATOR  //  BAYOU BYTES  //  EVERY TUESDAY

Reply

Avatar

or to participate