BENCH.B — OWASP Juice Shop

Reproducible. Unredacted. Inspectable end to end.

Bug bounty results prove real-world depth. Juice Shop proves that the same SecHive reporting style can be inspected end to end on a safe, intentionally vulnerable target. Routes, payloads, source references and evidence snippets are retained.

§ Coverage

Challenge coverage snapshot.

The Juice Shop source defines 111 challenges. SecHive findings are not the same object as scoreboard unlocks; we report challenge-equivalent coverage for sizing the gap.

Run styleCoveredGapNotes
Latest live runtime35 / 11176Runtime findings backed by live target behavior and evidence artifacts.
Latest source-aware58 / 1115335 runtime findings + 23 source-analysis candidates + 2 source-review candidates.
Archived black-box reference32 / 11179Earlier public report retained for reproducibility.
Archived white-box reference55 / 11156Source-candidate separation kept for audit trail.

Top runtime findings.

  1. JS.01SQL injection — auth bypassDirect authentication impact with observable success markers.critical
  2. JS.02Admin role injection on registerPrivilege assignment accepted from client-controlled input.critical
  3. JS.03SQL injection — data extractionInjection extends beyond login into data access behavior.critical
  4. JS.04IDOR — user / feedback / basketObject authorization gap across multiple resource classes.high
  5. JS.05XXE — file disclosureParser-level file disclosure behavior.high
  6. JS.06SSRF — internal fetchServer-side request behavior controlled by user input.high
  7. JS.07Session token replay after logoutSession invalidation and replay resistance gap.high

Why this can be full-fidelity.

The bug bounty corpus is redacted because it comes from live programs. Juice Shop is an intentionally vulnerable benchmark, so routes, payloads, source references, evidence snippets and remediation notes remain intact in the published report.

Reproduce. The published reports include image digests, run-mode labels, scope policy and the proof pack hash. A reviewer can rerun the campaign and verify result deltas line by line.
SecHive Juice Shop coverage