Skip to main content

Zoo Text-to-CAD Platform

Type

Security review

Client

Zoo

Date

2026-03

Domain

AppSec

Effort

4 wks

Section

Technology Product Reviews

Trail of Bits's security review of Zoo (Mar 2026) identified 13 issues: 1 high, 3 medium, 6 low, and 3 informational.

Findings · 13

  1. 1 SAML ancestor marking allows unsigned content to survive signature reduction Low
  2. 2 Logic error in get_signed_node returns ds:Object content instead of Reference URI target Low
  3. 3 XPointer URI resolution discrepancy could enable signature bypass Low
  4. 4 XPath transform discrepancy could allow unsigned content to be treated as signed Low
  5. 5 Pull request preview environments can be accessed by anyone via the user-controlled pr parameter Low
  6. 6 Account linking based on OIDC email claims could enable account takeover Low
  7. 7 The text-to-CAD service can be invoked by any internal service due to a lack of authentication and network isolation Medium
  8. 8 The auth_via_websocket panics when too many headers are sent Informational
  9. 9 Hard-coded secret in STUNner Kubernetes manifest Medium
  10. 10 WebSocket billing bypass vulnerability via URL encoding in path detection Medium
  11. 11 URL-encoded path traversal vulnerability in documentation fetching Informational
  12. 12 URL-encoded path traversal vulnerability in sample file fetching Informational
  13. 13 Arbitrary file write vulnerability in the /file/conversion API endpoint via absolute path in multipart filename High

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related