Details
Alert ID 210004-1
Alert Type Tool
Status alpha
Risk Medium
CWE 601
WASC
Technologies Targeted All
Tags CWE-601
OWASP_2021_A01
OWASP_2025_A01
TOOL_PTK

Summary

Client route state influenced history.replaceState. Generated by OWASP PTK IAST Module

Solution

• Do not derive navigation decisions directly from attacker-controlled route state. • Normalize and allow-list client routes before mutating browser history or SPA navigation.

Other Info

References

Code

src/ptk/background/iast/modules/modules.json