security
Attack Chains
Three medium findings can be one critical. We show you which.
What you get
Ranked by what an attacker can do
A leaked key is bad. A table without row-level security is bad. Together they are your database, readable by anyone. ZipLoom ranks the chain one step above its worst member and lists it before any single finding.
Code and live site, together
Chains span the source scan and the live posture check — a script-injection sink in the code plus no Content-Security-Policy on the deployed site is one chain, not two unrelated tickets.
The one fix that breaks it
Every chain names the step to fix first. Break that link and the path is gone, even if the other findings stay on your list for later.
How chains are built
- 1
Every open finding from your latest code scan and live posture check is collected per repository.
- 2
Findings are matched against known exploit paths — credential to data, unauthenticated injection, script injection without a browser backstop, cross-site requests riding a session.
- 3
A chain forms only when every step is present; same-file steps rank higher because the path is more likely real.
- 4
Chains appear above single findings in Security → Findings and in your coding agent over MCP.
What this check inspects
Exposed credentials combined with tables that have no row-level protection.
Unauthenticated routes that pass input into a query, command, file path or outbound request.
Unescaped HTML rendering on a site that sends no effective Content-Security-Policy.
Credentialed cross-origin access combined with cookies that lack SameSite protection.
What it means when this fails
A flat list sorted by severity hides the combinations. Teams fix the lone critical, defer three mediums, and ship the exact path an attacker needed — each piece looked tolerable on its own.
Questions
- I accepted one of these findings. Why is it in a chain?
- Because an accepted risk on its own can be a live path in combination. The chain flags that it includes an accepted finding so you can take a second look.
- Does every plan get chains?
- Yes — chains are part of the Brain console on every plan, within your monthly scan allowance.
Related features
Security Scan on Every Deploy
Catch RLS gaps, secret leaks, and CVEs before your app is reachable.
Learn moreLive Posture Scan on Your Deployed URL
External header, TLS, cookie, and DNS checks against the running site.
Learn moreLockdown Check — Row-Level Security
The RLS check whose absence caused CVE-2025-48757 — it fires before build.
Learn more