VolleyPacket
Libero Phase 1 · attack success rate report · July 2026
A full attack harness run against VolleyPacket before and after hardening. Sixteen suites, from account isolation to server side request forgery. Before: 33 of 53 attacks landed. After: 0 of 55.
The AI drafting features must fence untrusted data as data, cap oversized input that runs up cost, and clean anything saved so it cannot run in a browser later.
before 6 / 6 attacks landed · after 0 / 6
The protective response headers must be present: content type, framing, transport security, and content policy.
before 5 / 5 attacks landed · after 0 / 5
The mail path must not be pointable at internal hosts or forced into cleartext.
before 2 / 2 attacks landed · after 0 / 2
Personalization fields must not inject active content into generated documents or emails.
before 2 / 2 attacks landed · after 0 / 2
Two actions racing at once must not produce a double charge or a duplicate send.
before 1 / 1 attacks landed · after 0 / 1
A crafted name must not escape its folder to read or write files elsewhere.
before 1 / 1 attacks landed · after 0 / 1
Rendering must not be steerable to reach internal addresses or read local files.
before 1 / 1 attacks landed · after 0 / 1
A request must not consume unbounded memory or time, for example a decompression bomb.
before 1 / 1 attacks landed · after 0 / 2
A user supplied URL must not make the server fetch internal or private addresses.
before 1 / 1 attacks landed · after 0 / 2
One account's records must never be reachable by another account.
before 9 / 16 attacks landed · after 0 / 16
Values from an uploaded spreadsheet must not become live formulas when exported or opened elsewhere.
before 1 / 2 attacks landed · after 0 / 2
A forged, altered, or unsigned login token must be rejected, so nobody can act as another user.
before 2 / 6 attacks landed · after 0 / 6
Plan limits and billing state must not be bypassable or spoofable by the client.
before 1 / 3 attacks landed · after 0 / 3
Each account's saved provider credentials stay private to that account and are never exposed.
before 0 / 4 attacks landed · after 0 / 4
User text with line breaks must not inject extra email or HTTP headers.
before 0 / 1 attacks landed · after 0 / 1
A malformed or hostile upload must not crash or exploit the parser.
before 0 / 1 attacks landed · after 0 / 1