Snapshot 887916cf80e9417a, 1 Python file(s).
| Outcome | COMPLETED |
|---|---|
| Model | deepseek-flash via authorized_remote_owner_consent |
| Auditor (discovery) | SUCCEEDED |
| Lane agreement | AGREED |
| Architect (repair) | SUCCEEDED |
| Patch | PROPOSED |
| Validation | PASSED (parse PARSED, rescan signals 0) |
| Source checkout changed | no |
| CWE | OWASP Top 10 | Severity | Location | Found by |
|---|---|---|---|---|
| CWE-89 | A03:2021 Injection | HIGH | app.py:5 | deterministic + model |
Proposed by the Architect model and validated in an ephemeral copy (not applied to the source checkout):
--- a/app.py
+++ b/app.py
@@ -2,4 +2,4 @@
def find_user(conn, name):
- return conn.execute("SELECT * FROM users WHERE name = '" + name + "'")
+ return conn.execute("SELECT * FROM users WHERE name = ?", (name,))