fal-studio

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In the app flow, outsider-authored text (the user’s prompt and optional uploaded image URL) is ingested at runtime via the app’s server route (app/api/fal/proxy/route.ts/POST(req) in references/fal-runtime.md) where prompt is validated and then passed into fal.queue.submit(... input: { prompt: body.prompt, ... }).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 03:28 AM
Issues
1
Security Audit — snyk — fal-studio