Guided pathThis is part of Understand security: protocols, identity and secure architectureBack to the path

Injection & the untrusted-input lens

P57.vuln-classes.01 · Audience: guest, it-ml, language-pro · Prerequisites: AuthZ models: RBAC, ABAC, ReBAC

Real LLM grading for this pageLLM grading (this page):

Welcome to Application & API Security — the first pillar of Domain C, and where the protocol and identity knowledge of P52–P56 meets the code you actually write. One mental model covers a whole family of bugs: untrusted input that crosses a trust boundary and gets interpreted as code. This track instantiates it twice — in SQL, and in the path resolver.

Same thread as every module here: concept → protocol → attack → defence. Every kata is fix-the-function: hostile strings appear only as test inputs your defence must neutralise, and the graded work is always the fix.

The code runs entirely in your browser (Pyodide) against stubbed APIs — no real database, shell, or filesystem is involved.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — fix a SQL-injectable query builder

Loading exercise…

Rung 2 — confine a file path (stop traversal)

Loading exercise…

My notes on this module

Loading your notes...

Injection & the untrusted-input lens — TransformerLab