
route-detect
Find authentication (authn) and authorization (authz) security bugs in web application routes.
authenticationstatic-analysisvulnerability-analysis+1
280

Find authentication (authn) and authorization (authz) security bugs in web application routes.

CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain