Skip to content

#82 · New Security Test: Stack Trace Disclosure Detection

We've added a new security test to detect detailed error messages and stack trace disclosures, which can expose sensitive system details such as file paths, code snippets, and internal IPs. This test is now included by default in Escape's DAST.

When you return clear technical error information in a response, attackers might use that information to identify the specific technologies you're using, making it easier for them to target known vulnerabilities in those systems.

Here you can find an example:

Screenshot 2025-02-28 at 16.33.17.png

It's important to sanitize or hide these detailed errors and only log them internally so that you protect your application's inner workings from potential exploitation.

Learn more in our documentation.