Platform Update7 October 2026

AI Pentesting Now Confirms SSRF, XXE and Command Injection, and Tests Far More of Your Site

AI Pentesting Now Confirms SSRF, XXE and Command Injection, and Tests Far More of Your Site

AI Pentesting Now Confirms SSRF, XXE and Command Injection, and Tests Far More of Your Site

When we launched AI Pentesting, we were clear about its limits. It confirmed SQL injection and cross-site scripting with real proof, tested a fairly narrow slice of what a scan found, and didn't yet attempt SSRF, XXE or command injection.

This update closes a good part of that gap. AI Pentesting now covers more vulnerability classes, tests much more of each site, works on modern single-page apps and feeds its results into your headline score.

More vulnerability classes, each confirmed with proof

Every check still uses a real, named tool inside a sandbox, and still only reports "confirmed" when it has reproducible proof rather than a pattern match. The toolkit is now:

ToolWhat it confirms
sqlmapSQL injection in query parameters, API endpoints and form fields
dalfoxCross-site scripting, with execution verified in the DOM rather than just reflection
commixOS command injection, using a harmless, non-destructive probe
nuclei (out-of-band)SSRF and XXE
ffufHidden and sensitive parameter discovery
nuclei (exposure)Misconfigurations and exposed-file signatures
jwt_toolWeak JWT signing secrets

The SSRF and XXE checks deserve a word, because they work differently. Both vulnerabilities make your server fetch something it shouldn't, and often nothing comes back in the response to prove it. So we confirm them out of band: the test asks your server to contact a canary address that we control. If your server calls the canary, the vulnerability is real. If it doesn't, there's nothing to report. That is a clean yes or no, not a guess based on how a response looks.

Far more of your site gets tested

Before, the pentester only went after a small set of targets. Now it builds targets from everything the scan actually saw:

When we find an endpoint with no parameter to attack, we now try a curated set of the parameter names most often found to be injectable. That way, a bare endpoint still gets a meaningful test instead of being skipped.

Targets still come only from what the scan observed, plus that fixed list of well-known paths. The AI does not invent targets mid-scan, so the scope stays predictable and the consent you give still means something.

It now works on single-page apps

This was the biggest blind spot. Apps built with Angular, React or Vue often load almost everything through JavaScript, so a crawler that follows links finds very little. Some API-first apps used to come back with nothing to test.

API discovery now reads endpoints straight out of the application's JavaScript, including minified bundles, rather than relying on simple fetch or axios patterns. We checked this against OWASP Juice Shop, a deliberately vulnerable Angular app. The full scan now discovers its API and confirms a real SQL injection through the live pipeline.

Better defaults, so serious issues aren't missed

We tuned each tool's defaults so it catches real problems out of the box. The biggest change was sqlmap's detection depth. The old default was missing real injections without any warning. The new one confirms them, and it still uses a polite, non-destructive testing approach. Exposure templates are now bundled in advance, so scans don't depend on downloading anything mid-run.

Confirmed exploits now affect your Security Score

Until now, a confirmed exploit didn't change your overall Security Score. That was a timing problem, not a choice. AI Pentesting runs as a separate, longer phase after the main scan, and the overall score had already been calculated by the time it finished.

The overall score is now recalculated when the pentest phase completes. A confirmed exploit pulls the headline grade down, as it should. Informational and inconclusive results don't move it.

The scan-complete email has changed to match. It now waits for the pentest to finish, then shows all three scores together: the overall Security Score, the Active Testing Score and the AI Pentesting Score. The numbers in your inbox are the final results.

Faster and leaner under the hood

Each target is now tested in one isolated sandbox that runs all of its tools together, instead of one sandbox per tool. That means roughly five times fewer sandboxes per scan, which makes scans faster, cheaper to run and more robust, with the same coverage. Every run is still in a fresh sandbox, with network access limited to the target being tested, and destroyed afterwards.

We also fixed two crawler issues found along the way. The scan agent could keep re-checking the same source maps and third-party domains instead of moving on. Separately, quoted links embedded in a page could produce malformed URLs that the crawler would chase. Both fixes make scans faster and cleaner.

Tested end to end

We validated the changes against a deliberately vulnerable live application, confirming a real SQL injection through the complete scan pipeline. They are also covered by an expanded automated test suite of 72 tests.

What it still doesn't do

Our honest list of gaps is shorter than it was, but there still is one. AI Pentesting doesn't yet test for CSRF, or for broken access control such as IDOR and BOLA, where one user can reach another user's data. Those need an authenticated session and an understanding of who should see what, and we want to get them right rather than fast.

It is still continuous, evidence-backed testing between human-led tests, not a replacement when a contract, auditor or regulator requires a formal penetration test.

How to get it

AI Pentesting is part of the Enterprise plan, on top of Active Testing. It needs a second consent checkbox for each scan, and you should only run it against sites you own or are authorised to test. If you're already on Enterprise, your next scan uses everything above automatically.


From "this looks wrong" to "here's the proof". See how AI Pentesting works →