Submit Vulnerability
Submits a vulnerability against a target. The target must be live and one you have access to. At least one validation step must include an attachment.
curl --request POST \
--url https://platform.synack.com/api/v1/vulnerabilities \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"listingId": "k3v9x2mq7d",
"title": "SQL injection in the login API",
"description": "The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.",
"impact": "An unauthenticated attacker can read every row of the users table.",
"recommendedFix": "Use a parameterized query for the login lookup.",
"cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"vulnerabilityCategory": "sql_injection/sql_injection",
"exploitableLocations": [
{
"type": "url",
"value": "https://api.example.com/api/login",
"assetsUids": [
"9f1c2b3a1d0f2e3a4b5c"
]
}
],
"httpRequests": [
{
"httpRequest": "POST /api/login HTTP/1.1\nHost: api.example.com\nContent-Type: application/json\n\n{\"username\":\"admin' OR 1=1 -- \",\"password\":\"x\"}\n",
"vulnParam": "username",
"attackPayload": "' OR 1=1 -- "
}
],
"validationSteps": [
{
"detail": "Send the request above and observe a 200 response with an admin session cookie.",
"attachments": [
{
"id": 8412773,
"secureHash": "6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d"
}
]
}
],
"cvesCwes": [
"CWE-89"
]
}
EOFimport requests
url = "https://platform.synack.com/api/v1/vulnerabilities"
payload = {
"listingId": "k3v9x2mq7d",
"title": "SQL injection in the login API",
"description": "The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.",
"impact": "An unauthenticated attacker can read every row of the users table.",
"recommendedFix": "Use a parameterized query for the login lookup.",
"cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"vulnerabilityCategory": "sql_injection/sql_injection",
"exploitableLocations": [
{
"type": "url",
"value": "https://api.example.com/api/login",
"assetsUids": ["9f1c2b3a1d0f2e3a4b5c"]
}
],
"httpRequests": [
{
"httpRequest": "POST /api/login HTTP/1.1
Host: api.example.com
Content-Type: application/json
{\"username\":\"admin' OR 1=1 -- \",\"password\":\"x\"}
",
"vulnParam": "username",
"attackPayload": "' OR 1=1 -- "
}
],
"validationSteps": [
{
"detail": "Send the request above and observe a 200 response with an admin session cookie.",
"attachments": [
{
"id": 8412773,
"secureHash": "6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d"
}
]
}
],
"cvesCwes": ["CWE-89"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
listingId: 'k3v9x2mq7d',
title: 'SQL injection in the login API',
description: 'The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.',
impact: 'An unauthenticated attacker can read every row of the users table.',
recommendedFix: 'Use a parameterized query for the login lookup.',
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H',
vulnerabilityCategory: 'sql_injection/sql_injection',
exploitableLocations: [
{
type: 'url',
value: 'https://api.example.com/api/login',
assetsUids: ['9f1c2b3a1d0f2e3a4b5c']
}
],
httpRequests: [
{
httpRequest: 'POST /api/login HTTP/1.1\nHost: api.example.com\nContent-Type: application/json\n\n{"username":"admin\' OR 1=1 -- ","password":"x"}\n',
vulnParam: 'username',
attackPayload: '\' OR 1=1 -- '
}
],
validationSteps: [
{
detail: 'Send the request above and observe a 200 response with an admin session cookie.',
attachments: [{id: 8412773, secureHash: '6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d'}]
}
],
cvesCwes: ['CWE-89']
})
};
fetch('https://platform.synack.com/api/v1/vulnerabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://platform.synack.com/api/v1/vulnerabilities",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'listingId' => 'k3v9x2mq7d',
'title' => 'SQL injection in the login API',
'description' => 'The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.',
'impact' => 'An unauthenticated attacker can read every row of the users table.',
'recommendedFix' => 'Use a parameterized query for the login lookup.',
'cvssVector' => 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H',
'vulnerabilityCategory' => 'sql_injection/sql_injection',
'exploitableLocations' => [
[
'type' => 'url',
'value' => 'https://api.example.com/api/login',
'assetsUids' => [
'9f1c2b3a1d0f2e3a4b5c'
]
]
],
'httpRequests' => [
[
'httpRequest' => 'POST /api/login HTTP/1.1
Host: api.example.com
Content-Type: application/json
{"username":"admin\' OR 1=1 -- ","password":"x"}
',
'vulnParam' => 'username',
'attackPayload' => '\' OR 1=1 -- '
]
],
'validationSteps' => [
[
'detail' => 'Send the request above and observe a 200 response with an admin session cookie.',
'attachments' => [
[
'id' => 8412773,
'secureHash' => '6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d'
]
]
]
],
'cvesCwes' => [
'CWE-89'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.synack.com/api/v1/vulnerabilities"
payload := strings.NewReader("{\n \"listingId\": \"k3v9x2mq7d\",\n \"title\": \"SQL injection in the login API\",\n \"description\": \"The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.\",\n \"impact\": \"An unauthenticated attacker can read every row of the users table.\",\n \"recommendedFix\": \"Use a parameterized query for the login lookup.\",\n \"cvssVector\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n \"vulnerabilityCategory\": \"sql_injection/sql_injection\",\n \"exploitableLocations\": [\n {\n \"type\": \"url\",\n \"value\": \"https://api.example.com/api/login\",\n \"assetsUids\": [\n \"9f1c2b3a1d0f2e3a4b5c\"\n ]\n }\n ],\n \"httpRequests\": [\n {\n \"httpRequest\": \"POST /api/login HTTP/1.1\\nHost: api.example.com\\nContent-Type: application/json\\n\\n{\\\"username\\\":\\\"admin' OR 1=1 -- \\\",\\\"password\\\":\\\"x\\\"}\\n\",\n \"vulnParam\": \"username\",\n \"attackPayload\": \"' OR 1=1 -- \"\n }\n ],\n \"validationSteps\": [\n {\n \"detail\": \"Send the request above and observe a 200 response with an admin session cookie.\",\n \"attachments\": [\n {\n \"id\": 8412773,\n \"secureHash\": \"6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d\"\n }\n ]\n }\n ],\n \"cvesCwes\": [\n \"CWE-89\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://platform.synack.com/api/v1/vulnerabilities")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"listingId\": \"k3v9x2mq7d\",\n \"title\": \"SQL injection in the login API\",\n \"description\": \"The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.\",\n \"impact\": \"An unauthenticated attacker can read every row of the users table.\",\n \"recommendedFix\": \"Use a parameterized query for the login lookup.\",\n \"cvssVector\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n \"vulnerabilityCategory\": \"sql_injection/sql_injection\",\n \"exploitableLocations\": [\n {\n \"type\": \"url\",\n \"value\": \"https://api.example.com/api/login\",\n \"assetsUids\": [\n \"9f1c2b3a1d0f2e3a4b5c\"\n ]\n }\n ],\n \"httpRequests\": [\n {\n \"httpRequest\": \"POST /api/login HTTP/1.1\\nHost: api.example.com\\nContent-Type: application/json\\n\\n{\\\"username\\\":\\\"admin' OR 1=1 -- \\\",\\\"password\\\":\\\"x\\\"}\\n\",\n \"vulnParam\": \"username\",\n \"attackPayload\": \"' OR 1=1 -- \"\n }\n ],\n \"validationSteps\": [\n {\n \"detail\": \"Send the request above and observe a 200 response with an admin session cookie.\",\n \"attachments\": [\n {\n \"id\": 8412773,\n \"secureHash\": \"6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d\"\n }\n ]\n }\n ],\n \"cvesCwes\": [\n \"CWE-89\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://platform.synack.com/api/v1/vulnerabilities")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"listingId\": \"k3v9x2mq7d\",\n \"title\": \"SQL injection in the login API\",\n \"description\": \"The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.\",\n \"impact\": \"An unauthenticated attacker can read every row of the users table.\",\n \"recommendedFix\": \"Use a parameterized query for the login lookup.\",\n \"cvssVector\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n \"vulnerabilityCategory\": \"sql_injection/sql_injection\",\n \"exploitableLocations\": [\n {\n \"type\": \"url\",\n \"value\": \"https://api.example.com/api/login\",\n \"assetsUids\": [\n \"9f1c2b3a1d0f2e3a4b5c\"\n ]\n }\n ],\n \"httpRequests\": [\n {\n \"httpRequest\": \"POST /api/login HTTP/1.1\\nHost: api.example.com\\nContent-Type: application/json\\n\\n{\\\"username\\\":\\\"admin' OR 1=1 -- \\\",\\\"password\\\":\\\"x\\\"}\\n\",\n \"vulnParam\": \"username\",\n \"attackPayload\": \"' OR 1=1 -- \"\n }\n ],\n \"validationSteps\": [\n {\n \"detail\": \"Send the request above and observe a 200 response with an admin session cookie.\",\n \"attachments\": [\n {\n \"id\": 8412773,\n \"secureHash\": \"6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d\"\n }\n ]\n }\n ],\n \"cvesCwes\": [\n \"CWE-89\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"vulnerability": {
"id": "aardvarkquiet-58",
"listingId": "k3v9x2mq7d",
"title": "SQL injection in the login API",
"description": "<string>",
"impact": "<string>",
"recommendedFix": "<string>",
"vulnerabilityCategory": "SQL Injection",
"vulnerabilitySubcategory": "SQL Injection",
"state": "open",
"cvssVersion": "3.1",
"cvssFinal": "9.8",
"createdAt": "2026-08-13T14:22:05Z",
"resolvedAt": "2026-08-14T09:03:11Z"
}
}Authorizations
API token generated in the researcher portal under your profile menu, API, Tokens.
Body
Slug of the target, as shown in the target's URL in the researcher portal.
"k3v9x2mq7d"
Vulnerability title.
1 - 255What the vulnerability is and where it occurs. Supports Markdown.
10 - 21000What an attacker can achieve by exploiting it. Supports Markdown.
10 - 21000How the customer can remediate it. Supports Markdown.
1 - 22000CVSS 3.0, 3.1 or 4.0 base vector. Every base metric is required. The CVSS version and score are calculated from it.
^CVSS:(3\.[01]|4\.0)/"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
At most 100,000 characters in total.
1Show child attributes
Show child attributes
Steps to reproduce the vulnerability. At least one step must include an attachment. At most 25 attachments per step and 50 across all steps.
1 - 50 elementsShow child attributes
Show child attributes
Category ID, in the form parent/child. If omitted or other/other, vulnerabilityCategoryOther is used instead.
"sql_injection/sql_injection"
Free-text category, used when vulnerabilityCategory is omitted or other/other. Defaults to Not categorized.
255At most 100,000 characters in total.
Show child attributes
Show child attributes
Researchers to share the payout with.
5Show child attributes
Show child attributes
CVE and CWE IDs. Duplicates are removed. The combined length of the IDs must not exceed 100 characters.
["CVE-2024-12345", "CWE-89"]
Response
The vulnerability was submitted.
Vulnerability description.
Show child attributes
Show child attributes
curl --request POST \
--url https://platform.synack.com/api/v1/vulnerabilities \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"listingId": "k3v9x2mq7d",
"title": "SQL injection in the login API",
"description": "The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.",
"impact": "An unauthenticated attacker can read every row of the users table.",
"recommendedFix": "Use a parameterized query for the login lookup.",
"cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"vulnerabilityCategory": "sql_injection/sql_injection",
"exploitableLocations": [
{
"type": "url",
"value": "https://api.example.com/api/login",
"assetsUids": [
"9f1c2b3a1d0f2e3a4b5c"
]
}
],
"httpRequests": [
{
"httpRequest": "POST /api/login HTTP/1.1\nHost: api.example.com\nContent-Type: application/json\n\n{\"username\":\"admin' OR 1=1 -- \",\"password\":\"x\"}\n",
"vulnParam": "username",
"attackPayload": "' OR 1=1 -- "
}
],
"validationSteps": [
{
"detail": "Send the request above and observe a 200 response with an admin session cookie.",
"attachments": [
{
"id": 8412773,
"secureHash": "6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d"
}
]
}
],
"cvesCwes": [
"CWE-89"
]
}
EOFimport requests
url = "https://platform.synack.com/api/v1/vulnerabilities"
payload = {
"listingId": "k3v9x2mq7d",
"title": "SQL injection in the login API",
"description": "The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.",
"impact": "An unauthenticated attacker can read every row of the users table.",
"recommendedFix": "Use a parameterized query for the login lookup.",
"cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"vulnerabilityCategory": "sql_injection/sql_injection",
"exploitableLocations": [
{
"type": "url",
"value": "https://api.example.com/api/login",
"assetsUids": ["9f1c2b3a1d0f2e3a4b5c"]
}
],
"httpRequests": [
{
"httpRequest": "POST /api/login HTTP/1.1
Host: api.example.com
Content-Type: application/json
{\"username\":\"admin' OR 1=1 -- \",\"password\":\"x\"}
",
"vulnParam": "username",
"attackPayload": "' OR 1=1 -- "
}
],
"validationSteps": [
{
"detail": "Send the request above and observe a 200 response with an admin session cookie.",
"attachments": [
{
"id": 8412773,
"secureHash": "6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d"
}
]
}
],
"cvesCwes": ["CWE-89"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
listingId: 'k3v9x2mq7d',
title: 'SQL injection in the login API',
description: 'The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.',
impact: 'An unauthenticated attacker can read every row of the users table.',
recommendedFix: 'Use a parameterized query for the login lookup.',
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H',
vulnerabilityCategory: 'sql_injection/sql_injection',
exploitableLocations: [
{
type: 'url',
value: 'https://api.example.com/api/login',
assetsUids: ['9f1c2b3a1d0f2e3a4b5c']
}
],
httpRequests: [
{
httpRequest: 'POST /api/login HTTP/1.1\nHost: api.example.com\nContent-Type: application/json\n\n{"username":"admin\' OR 1=1 -- ","password":"x"}\n',
vulnParam: 'username',
attackPayload: '\' OR 1=1 -- '
}
],
validationSteps: [
{
detail: 'Send the request above and observe a 200 response with an admin session cookie.',
attachments: [{id: 8412773, secureHash: '6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d'}]
}
],
cvesCwes: ['CWE-89']
})
};
fetch('https://platform.synack.com/api/v1/vulnerabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://platform.synack.com/api/v1/vulnerabilities",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'listingId' => 'k3v9x2mq7d',
'title' => 'SQL injection in the login API',
'description' => 'The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.',
'impact' => 'An unauthenticated attacker can read every row of the users table.',
'recommendedFix' => 'Use a parameterized query for the login lookup.',
'cvssVector' => 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H',
'vulnerabilityCategory' => 'sql_injection/sql_injection',
'exploitableLocations' => [
[
'type' => 'url',
'value' => 'https://api.example.com/api/login',
'assetsUids' => [
'9f1c2b3a1d0f2e3a4b5c'
]
]
],
'httpRequests' => [
[
'httpRequest' => 'POST /api/login HTTP/1.1
Host: api.example.com
Content-Type: application/json
{"username":"admin\' OR 1=1 -- ","password":"x"}
',
'vulnParam' => 'username',
'attackPayload' => '\' OR 1=1 -- '
]
],
'validationSteps' => [
[
'detail' => 'Send the request above and observe a 200 response with an admin session cookie.',
'attachments' => [
[
'id' => 8412773,
'secureHash' => '6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d'
]
]
]
],
'cvesCwes' => [
'CWE-89'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://platform.synack.com/api/v1/vulnerabilities"
payload := strings.NewReader("{\n \"listingId\": \"k3v9x2mq7d\",\n \"title\": \"SQL injection in the login API\",\n \"description\": \"The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.\",\n \"impact\": \"An unauthenticated attacker can read every row of the users table.\",\n \"recommendedFix\": \"Use a parameterized query for the login lookup.\",\n \"cvssVector\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n \"vulnerabilityCategory\": \"sql_injection/sql_injection\",\n \"exploitableLocations\": [\n {\n \"type\": \"url\",\n \"value\": \"https://api.example.com/api/login\",\n \"assetsUids\": [\n \"9f1c2b3a1d0f2e3a4b5c\"\n ]\n }\n ],\n \"httpRequests\": [\n {\n \"httpRequest\": \"POST /api/login HTTP/1.1\\nHost: api.example.com\\nContent-Type: application/json\\n\\n{\\\"username\\\":\\\"admin' OR 1=1 -- \\\",\\\"password\\\":\\\"x\\\"}\\n\",\n \"vulnParam\": \"username\",\n \"attackPayload\": \"' OR 1=1 -- \"\n }\n ],\n \"validationSteps\": [\n {\n \"detail\": \"Send the request above and observe a 200 response with an admin session cookie.\",\n \"attachments\": [\n {\n \"id\": 8412773,\n \"secureHash\": \"6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d\"\n }\n ]\n }\n ],\n \"cvesCwes\": [\n \"CWE-89\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://platform.synack.com/api/v1/vulnerabilities")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"listingId\": \"k3v9x2mq7d\",\n \"title\": \"SQL injection in the login API\",\n \"description\": \"The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.\",\n \"impact\": \"An unauthenticated attacker can read every row of the users table.\",\n \"recommendedFix\": \"Use a parameterized query for the login lookup.\",\n \"cvssVector\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n \"vulnerabilityCategory\": \"sql_injection/sql_injection\",\n \"exploitableLocations\": [\n {\n \"type\": \"url\",\n \"value\": \"https://api.example.com/api/login\",\n \"assetsUids\": [\n \"9f1c2b3a1d0f2e3a4b5c\"\n ]\n }\n ],\n \"httpRequests\": [\n {\n \"httpRequest\": \"POST /api/login HTTP/1.1\\nHost: api.example.com\\nContent-Type: application/json\\n\\n{\\\"username\\\":\\\"admin' OR 1=1 -- \\\",\\\"password\\\":\\\"x\\\"}\\n\",\n \"vulnParam\": \"username\",\n \"attackPayload\": \"' OR 1=1 -- \"\n }\n ],\n \"validationSteps\": [\n {\n \"detail\": \"Send the request above and observe a 200 response with an admin session cookie.\",\n \"attachments\": [\n {\n \"id\": 8412773,\n \"secureHash\": \"6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d\"\n }\n ]\n }\n ],\n \"cvesCwes\": [\n \"CWE-89\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://platform.synack.com/api/v1/vulnerabilities")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"listingId\": \"k3v9x2mq7d\",\n \"title\": \"SQL injection in the login API\",\n \"description\": \"The `username` parameter of POST /api/login is concatenated into a SQL statement without parameterization.\",\n \"impact\": \"An unauthenticated attacker can read every row of the users table.\",\n \"recommendedFix\": \"Use a parameterized query for the login lookup.\",\n \"cvssVector\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\",\n \"vulnerabilityCategory\": \"sql_injection/sql_injection\",\n \"exploitableLocations\": [\n {\n \"type\": \"url\",\n \"value\": \"https://api.example.com/api/login\",\n \"assetsUids\": [\n \"9f1c2b3a1d0f2e3a4b5c\"\n ]\n }\n ],\n \"httpRequests\": [\n {\n \"httpRequest\": \"POST /api/login HTTP/1.1\\nHost: api.example.com\\nContent-Type: application/json\\n\\n{\\\"username\\\":\\\"admin' OR 1=1 -- \\\",\\\"password\\\":\\\"x\\\"}\\n\",\n \"vulnParam\": \"username\",\n \"attackPayload\": \"' OR 1=1 -- \"\n }\n ],\n \"validationSteps\": [\n {\n \"detail\": \"Send the request above and observe a 200 response with an admin session cookie.\",\n \"attachments\": [\n {\n \"id\": 8412773,\n \"secureHash\": \"6f1c8a0d9b7e4f2a1c3d5e6f7a8b9c0d\"\n }\n ]\n }\n ],\n \"cvesCwes\": [\n \"CWE-89\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"vulnerability": {
"id": "aardvarkquiet-58",
"listingId": "k3v9x2mq7d",
"title": "SQL injection in the login API",
"description": "<string>",
"impact": "<string>",
"recommendedFix": "<string>",
"vulnerabilityCategory": "SQL Injection",
"vulnerabilitySubcategory": "SQL Injection",
"state": "open",
"cvssVersion": "3.1",
"cvssFinal": "9.8",
"createdAt": "2026-08-13T14:22:05Z",
"resolvedAt": "2026-08-14T09:03:11Z"
}
}