Skip to content

Release Notes

#99 · Enhanced Alert Justification with Screenshots and Code Snippets

We’re excited to announce a major enhancement to the justification process for detected vulnerabilities in our front-end DAST scanner!

Until now, you could only rely on HTTP requests to justify alerts — for example, looking at an HTTP request to demonstrate a vulnerability like an SQL injection. While this approach was effective, it had its limitations in conveying the full context of certain vulnerabilities.

Now, you can also include screenshots and code snippets to better justify alerts!

Recording-new-reprodu (1).gif

This new capability adds a much-needed layer of clarity, providing additional context and evidence that makes understanding and addressing vulnerabilities much easier.

See it for yourself:

Key Benefits:

  • Better Context: With screenshots and code snippets, you can now offer clearer evidence and documentation, making vulnerabilities easier to analyze and resolve.
  • Major Improvement for Frontend DAST: Frontend vulnerabilities often involve complex UIs and dynamic behaviors, and this enhancement simplifies the validation and remediation process.

We hope that this update will help you resolve vulnerabilities more effectively and efficiently, providing better visibility and documentation throughout the remediation process.

#98 · Enhanced Remediation Framework Selection for Frontend Scanner

We’ve enhanced the remediation process in our front-end scanner to help your teams close critical issues faster.

Previously, the framework for generating remediation code snippets was set by default. Now, users have the ability to select their preferred API framework when addressing API-related vulnerabilities, providing more flexibility and control over the remediation of issues.

This update gives you the flexibility to choose the framework that works best for you, making it easier and faster to resolve issues!

#97 · New Design for All Risks -> Issues Table

We’ve made several improvements to enhance the user experience with the All Risks -> Issues table. Here’s a breakdown of the new features:

  • Enhanced Application Selection: Users can now select applications either by label or individually, providing more flexibility in managing and viewing the issues per application type important for your business.
  • Jira Ticket Filter: We’ve added a filter for Jira tickets, allowing you to quickly and easily search and categorize issues linked to specific Jira tasks.
  • Sorting by Severity: The issues are sorted by default by severity, ensuring that the most critical issues are always prioritized and easily accessible.
  • Updated Funnel Stages: The stages for “High Business Impact” and “Critical” have been inverted in the funnel. Critical is now the most important stage, highlighting the highest priority issues.

Here is how your Issues Table will look now:

Screenshot 2025-03-25 at 16.49.36.png

We hope these updates help make navigating through issues faster and more efficient!

#94 · Long Scan Stability Improvement

Stability for extended scans has been significantly improved: We've resolved an issue caused by a Python bug that randomly interrupted and killed long scans. We’re confident this fix will ensure a smoother experience with Escape!

#93 · Authentication Improvements in DAST Scanning

We know how frustrating the authentication process in DAST scans can be, which is why we've made several key updates to streamline it! Our goal is to provide you with better flexibility and efficiency for your security testing needs.

Here's the full list:

1. Support for complex authentication scenarios

We now support more complex authentication processes through the new Browser Actions Authentication Preset. This is especially useful for scenarios where traditional authentication methods don’t work well. With Browser Actions, you can customize your authentication flow using browser actions rather than relying on Escape's AI agent. This is ideal for form-based authentication where inputs are provided directly by users.

The Browser Actions preset uses Playwright for browser automation actions, such as filling in forms and clicking buttons. By default, it extracts cookies, localStorage, and sessionStorage from the browser, injecting them into the scan engine for frontend scans. For API scans, only cookies are injected.

Key benefits:

  • Customize authentication flows using direct browser actions.
  • Automatically extract and inject cookies and storage (for frontend scans).
  • Configure extractions and injections for specific storage needs (e.g., local/session storage).

For detailed documentation and some examples of how you can set it up, visit: Browser Actions Authentication Preset.

2. Single Page Mode for Enterprise Applications

We’ve introduced a new Single Page Mode to handle use cases where enterprise applications allow only one user to be logged in at a time. This feature ensures that authentication is managed seamlessly in environments with strict session controls, eliminating the need for additional configurations or manual intervention. Once authenticated, the system will maintain that connection throughout the scan.

3. Automatic Reauthentication When the Tab Is Closed

For applications that automatically log users out when the tab is closed, our system now ensures that reauthentication is handled automatically. There's no need to reconfigure your DAST scan setup or manually log in again—everything is managed in the background, allowing for a smooth and uninterrupted scanning process.

4. Handling Applications with Single Tab Login Restrictions

In cases where applications do not allow multiple tabs to be logged in simultaneously, our updated DAST scanning process automatically manages reauthentication. This removes the hassle of managing tab states and ensures that your scan continues without the need to manually re-authenticate across multiple tabs.

The improvements we've made to our DAST scanning authentication process addressed the specific pain points our customers face, especially for complex or custom authentication systems! With these updates, you can now handle advanced authentication workflows, such as the one described above, without losing session continuity or compromising on scan effectiveness!

#92 · Added Graph Visualization in the Inventory

We’ve added a powerful new feature: the API Lifecycle Graph within the Inventory. This visualization allows you to see an in-depth view of your API service, including its lifecycle and key integration details.

api-lifecycle-graph.png

What you can view:

  • API Lifecycle Graph: View the full lifecycle of the API service.
  • Hosting Details: Know the domain where the API service is hosted, the cloud provider, the associated IP address, and the country where it’s hosted.
  • Service Integration: See the integration with Wiz, GitHub, GitLab, Kubernetes or others and how it was set up (e.g., via GitLab API key).
  • Repository Info: Identify the repository and associated URL where the service is hosted.
  • API Schema: View the associated API schema, how it was generated or found, and its endpoints with the methods linked to each endpoint.
  • Application Scan: See which application scan is associated with the service and view alerts linked to that application. Each alert is color-coded depending on its severity.

How to view:

  • Go to Inventory → All Services.
  • Click on the service you want to inspect.
  • You'll find the API Lifecycle Graph at the bottom of the Overview tab.

Benefits:

  • Complete Lifecycle Visibility: The API Lifecycle Graph provides a comprehensive view of your API’s entire journey, from integration to deployment.
  • Simplified Troubleshooting: By visualizing the API's integration and hosting details, you can easily identify potential points of failure or misconfigurations.
  • Better Monitoring and Tracking: Track the service repository, schema, and its endpoints efficiently in one place, making it easier to manage and secure your APIs.
  • Contextual Insights: View associated scans, vulnerabilities, and alerts in context, allowing you to quickly assess the security posture of your API services.

We hope that visually representing all relevant information helps you make informed decisions faster and improves your ability to monitor, manage, and secure your APIs effectively!

#91 · Advanced Configuration: Configure Headers in Playwright Authentication

We’ve added the PlaywrightUserPreset option to the advanced configuration settings. This allows you to inject optional headers during the authentication process and for authenticated requests, giving you more flexibility when setting up tests.

How to Set It Up:

  1. Go to the settings of the relevant app.
  2. Navigate to Scan configuration → Expert.
  3. Under presets,

use the following structure:

 presets: type: playwright
 type: playwright
 login_url: https://auth.example.com/login`
 users:
   header:

Benefits:

  • The preset feature makes it easier to configure authentication in Playwright-based testing, saving time and improving accuracy.
  • It allows you to inject custom headers, making it easier to handle complex authentication flows.
  • With the ability to configure headers, you can fine-tune authentication behavior to match your exact requirements.
  • Ensures that authenticated requests during scanning will include the necessary headers, reducing the chance of skipped or incorrect tests.

#90 · Enhanced "Visited Pages" Tab for Front-End Applications

For each tested front-end application, our "Visited Pages" tab has received an upgrade!

The Visited Pages tab plays a crucial role in your scan results. Unlike API scans, where there is a predefined list of endpoints, front-end scanning relies on a crawling system and security checks engine. This allows you to validate which pages were visited and the issues found on each crawl.

Screenshot 2025-03-07 at 16.41.45.png

What's New:

  • Grouping of Similar Pages: Pages are now grouped by default, helping you focus on key pages and reducing noise for more efficient analysis.

  • Improved Page Organization: Each visited group includes:

    • Page Name
    • Reached Status Code
    • Number of Visits by Scanner
    • Associated Findings (vulnerabilities in the page)
    • Sensitive Data Found
  • Filters: You can filter by:

    • Sensitive Data
    • Severity
    • Associated Vulnerability
    • Type of Finding (Vulnerability)
    • Status Code

If you prefer to see everything, you can still click on Show All for the full view.

This update brings improved efficiency and better organization, allowing you to focus on critical findings and reduce unnecessary noise!