WhisperX tag archive

#false-positive

This page collects WhisperX intelligence signals tagged #false-positive. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-01 11:27:20 · GitHub Issues

1. WAST RedirectScanner Hardcodes 'evil.com', Flooding Real Domain with Uncontrolled Traffic

The WAST security scanner's RedirectScanner module is hardcoded to send all its test traffic to the real, publicly registered domain 'evil.com'. This design flaw forces every scan to generate live DNS lookups and HTTP redirect attempts to a third-party host outside the project's control, creating an uncontrolled extern...

The Lab · 2026-04-08 08:27:04 · GitHub Issues

2. GitHub Issue: health-monitor.sh CPU allowlist creates security blind spot by suppressing all 'find' processes

A recent update to the `health-monitor.sh` monitoring script has introduced a significant security vulnerability. The fix for a noisy alert has inadvertently created a monitoring blind spot by adding the `find` command to a trusted high-CPU process allowlist. This suppresses alerts for *all* processes named `find` runn...