SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-807 Reliance on Untrusted Inputs in a Security Decision

Coverage: 5 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 5 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged a security decision being made using untrusted input (client-provided fields, headers, query params) without verification.

Why it matters

Trusting unverified input can enable bypasses and escalation.

Safer examples

1) Verify identity and roles server-side

Use server-validated sessions/tokens and load roles/permissions from the server.

2) Validate and allowlist inputs

Validate at the boundary and reject unexpected shapes (see CWE-20).

3) Recompute sensitive values server-side

Don't trust client totals/prices/state; recompute or verify with signatures (see A11).

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.