When a security reviewer comments on a pull request, it uses words like IDOR, tenant isolation or SSRF. Each entry below says what the word means in a sentence you can repeat, gives one everyday example, and shows what it looks like in a diff your coding agent might write.
Any way a user can see or do something the application meant to forbid: read another account's data, call an admin action, or edit a record they may only view. OWASP ranks it first in its 2021 Top 10.
Aevral PR review looks for this, under access control on its class list.
Read more: Reviewing a pull request for access control; What a whole-repo authorization scan reads. See also: IDOR, Authorization vs authentication, Least privilege.
A hole in the rules of the application rather than in its plumbing. Each step works as coded, but the order of steps or the rule itself lets someone reach an outcome the business never intended.
Aevral PR review looks for this, under business logic on its class list.
Read more: Where access control hides in business logic; PR review. See also: Broken access control.
An AI tool that reads and changes code, runs commands and tests, and works through a task with little step-by-step direction. Many can also open the pull request themselves.
Read more: Aevral for coding agents; Handing a security finding to your coding agent. See also: Pull request security review, Security finding.
Untrusted text, from a form, a link or stored content, ends up in a web page in a way the browser runs as code, so an attacker's script runs inside another user's session, with that user's access.
Aevral PR review looks for this, under XSS on its class list.
Read more: Cross-site scripting in agent-written code; PR review. See also: Prompt injection.
Insecure direct object reference
The application takes a record id from the request, such as an invoice number in the address, and reads or changes that record without checking that the caller is allowed to.
Aevral PR review looks for this, under access control on its class list.
Read more: How IDOR happens in multi-tenant code; Reviewing a pull request for access control. See also: Tenant isolation, Broken access control.
Give each person, service and key only the access its job needs, and nothing more, so a mistake or a stolen credential can do limited damage.
Read more: Reviewing a pull request for access control; Reviewing a pull request that wires in an LLM. See also: Broken access control, Prompt injection.
The application builds a file path from user input, and sequences like ../ walk out of the folder it meant to use, to read or write files elsewhere on the server.
Aevral PR review looks for this, under path traversal on its class list.
Read more: Path traversal in agent-written code; PR review. See also: SSRF.
Text that a language model follows as instructions even though it arrived as data: a web page, an email, a document or a form field. When the model can call tools, injected text can steer those tools.
Aevral PR review looks for this, under LLM-integration risks on its class list.
Read more: Reviewing a pull request that wires in an LLM; PR review. See also: Least privilege, SQL injection.
Reading a proposed code change for security before it ships: what the change lets someone do that they could not do before, such as reach data that is not theirs, run commands, or skip a check.
Read more: PR review; PR security review and SAST are different questions. See also: SAST, Security finding, Coding agent.
Static application security testing
Tools that read source code without running it and match it against known insecure patterns and data flows. They run across the codebase and suit well-defined, rule-shaped bugs.
Read more: PR security review and SAST are different questions; Vulnerability classes in agent-written code. See also: Pull request security review.
A reviewer's report that a specific piece of code may be exploitable: where it is, what could go wrong, and what would fix it. A good one is a lead with evidence for a person to check, not a verdict.
Read more: Handing a security finding to your coding agent; Receipts: named test runs, misses included. See also: Pull request security review, Coding agent.
Text from a user is pasted into a database query, so the database reads part of it as query code instead of as a value, and the attacker changes what the query does.
Aevral PR review looks for this, under SQL and command injection on its class list.
Read more: SQL injection in agent-written code; PR review. See also: Prompt injection.
Server-side request forgery
The server fetches a web address the user chose, so an attacker can make it reach places only the server can reach, such as internal services or the cloud metadata address.
Aevral PR review looks for this, under SSRF on its class list.
Read more: SSRF in agent-written code; PR review. See also: Path traversal.
In software that serves many customer organizations from one system, tenant isolation keeps each organization's data and actions separate from every other organization's.
Aevral PR review looks for this, under access control on its class list.
Read more: How IDOR happens in multi-tenant code; Where access control hides in business logic. See also: IDOR, Broken access control.
Turning received bytes back into program objects with a loader that builds whatever objects the data names. With formats such as Python's pickle, loading attacker-controlled data can run code.
Aevral PR review looks for this, under unsafe deserialization on its class list.
Read more: Unsafe deserialization in agent-written code; PR review. See also: Prompt injection.
These are teaching definitions, not a standard. Aevral's PR security review, live on install, looks for the classes marked on this page; looking for a class does not mean finding each instance of it, and a finding is a lead for you to check. The whole-repo scan reads authorization, IDOR, and business-logic access control only. The examples are illustrations, not findings from real customer code. For the full coverage and its limits, see PR review; for named evaluation results with their misses, see the receipts.
One GitHub App. Reviews start when the App is installed. A Check on each pull request it reviews, with inline comments when there is a grounded finding. Free tier live: public repos free, 500/org/month, 25 private reviews a month. Paid plans are live in the console.
For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.