← Files get-fableARCHIVED FILE

skills/fable-security/templates/security-finding.template.md

628 Bytes · Oct 4, 2026 · 12:30 UTC

↓ Download file

# Security Advisory Finding: [Vulnerability Name]

## Advisory Metadata
- **Severity**: [CRITICAL / HIGH / MEDIUM / LOW]
- **CWE / Category**: [e.g. CWE-89: SQL Injection / Broken Access Control]
- **Affected File**: `src/api/routes.ts:L112`

## Vulnerability Description & Exploit Scenario
[Describe how an attacker could exploit the issue, trust boundaries breached, and data impact]

## Mitigated Implementation
```typescript
// Secure parameterized query replacing raw string concatenation
const result = await db.query(
  'SELECT id, email, role FROM users WHERE organization_id = $1 AND id = $2',
  [orgId, userId]
);
```

SHA-256: 4e2840168c8acc2c604963d4a2e8ba00c4bed24cf1262e9d49d1983c9885e050