← Files get-fableARCHIVED FILE
skills/fable-security/templates/security-finding.template.md
628 Bytes · Oct 4, 2026 · 12:30 UTC
# Security Advisory Finding: [Vulnerability Name] ## Advisory Metadata - **Severity**: [CRITICAL / HIGH / MEDIUM / LOW] - **CWE / Category**: [e.g. CWE-89: SQL Injection / Broken Access Control] - **Affected File**: `src/api/routes.ts:L112` ## Vulnerability Description & Exploit Scenario [Describe how an attacker could exploit the issue, trust boundaries breached, and data impact] ## Mitigated Implementation ```typescript // Secure parameterized query replacing raw string concatenation const result = await db.query( 'SELECT id, email, role FROM users WHERE organization_id = $1 AND id = $2', [orgId, userId] ); ```
SHA-256: 4e2840168c8acc2c604963d4a2e8ba00c4bed24cf1262e9d49d1983c9885e050