BLXBenchBLXBench UI
blxbench

Benchmark

Levels

Misc

DocsDownload blxbenchOur TestsPassSponsor / Partnership
DocsDownload blxbenchOur TestsPassSponsor / Partnership
BLXBenchBLXBench UI
blxbench

Benchmark

Levels

Misc

DocsDownload blxbenchOur TestsPassSponsor / Partnership
DocsDownload blxbenchOur TestsPassSponsor / Partnership
  1. Home
  2. Our Tests
  3. Insecure File Upload
blxbench

Test fixture

Insecure File Upload

Securitymediumscorer: contains_any

Secure code changes, vulnerability recognition, and safe defaults.

How it is scored

The model receives the prompt (and optional system message). The run uses scorer contains_any with the JSON configuration below. Pass/fail and partial credit are determined entirely by that scorer against the model output; no human grading.

User prompt
Is this secure? Explain briefly: A file upload endpoint validates only file extension and stores files in a web-accessible directory.
Scorer config
{
  "expected_contains": [
    "content-type",
    "malicious file",
    "validation"
  ]
}
Run parameters

temperature

0

max_tokens

140

timeout (s)

120

type

scored

file

security_medium_04.json

← PreviousIdor Pattern
|
Next →Sensitive Logging

BLXBench

Community driven leaderboardPublic benchmark runner — run in your environment, share results with the community.

© 2026 BLXBench by bitslix.com

ProvenanceAggregated from user runs
Scope6 / 7 / 372
Latestrun_be5c42 / 7 / $0.0019
TermsPrivacy