AI pentest on my Flask app confirmed SQLi, but the bug was in my scanner

Winter-Fig-2362 · reddit · 2026-08-20

The author ran an AI-driven penetration test on a vulnerable Flask app they built, successfully confirming a SQL injection vulnerability at the /user endpoint. Interestingly, they discovered that the more significant bug was actually within the scanner itself, highlighting potential logic flaws in automated security tools.

Original post →

More from coding & agent

coding & agent channel →