Audit Open Original ↗
Zoo Text-to-CAD Platform
Type
Security review
Client
Zoo
Date
2026-03
Domain
AppSec
Effort
4 wks
Section
Technology Product Reviews
Trail of Bits's security review of Zoo (Mar 2026) identified 13 issues: 1 high, 3 medium, 6 low, and 3 informational.
Findings · 13
- 1 SAML ancestor marking allows unsigned content to survive signature reduction Low
- 2 Logic error in get_signed_node returns ds:Object content instead of Reference URI target Low
- 3 XPointer URI resolution discrepancy could enable signature bypass Low
- 4 XPath transform discrepancy could allow unsigned content to be treated as signed Low
- 5 Pull request preview environments can be accessed by anyone via the user-controlled pr parameter Low
- 6 Account linking based on OIDC email claims could enable account takeover Low
- 7 The text-to-CAD service can be invoked by any internal service due to a lack of authentication and network isolation Medium
- 8 The auth_via_websocket panics when too many headers are sent Informational
- 9 Hard-coded secret in STUNner Kubernetes manifest Medium
- 10 WebSocket billing bypass vulnerability via URL encoding in path detection Medium
- 11 URL-encoded path traversal vulnerability in documentation fetching Informational
- 12 URL-encoded path traversal vulnerability in sample file fetching Informational
- 13 Arbitrary file write vulnerability in the /file/conversion API endpoint via absolute path in multipart filename High
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related