Skip to content
#

bfla

Here are 3 public repositories matching this topic...

Language: All
Filter by language
overstep

Authorization testing for MCP servers; works on HTTP APIs too. Turns an access-control matrix into positive & negative tests that catch BOLA, BFLA, BOPLA, privilege escalation, token-audience and session-binding flaws across tools and resources — with CWE/OWASP-tagged SARIF for CI/CD.

  • Updated Aug 13, 2026
  • Python

Improve this page

Add a description, image, and links to the bfla topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the bfla topic, visit your repo's landing page and select "manage topics."

Learn more