FastAPI Real-Time Features
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Source: WebSocket runtime path
/wsreceives outsider-authored JSON viawebsocket.receive_json()and forwards fields likecontenttobroadcast_to_room(...), so arbitrary user text can be ingested and processed by the workflow without selecting a specific trusted item first.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata