IDOR
HoldTechniques
Insecure Direct Object Reference, an access-control vulnerability where users can reach data belonging to others.
Why it's here
Placed in Hold: 1 article(s) of evidence from 1 source(s), led by research-stage coverage, with 0 in the last 30 days. Confidence 24%. Low accumulated evidence, so it defaults conservatively pending more signal.
Evidence (1)
- 7Hacker News·6/28/2026researchGLM 5.2 Outperforms Claude in IDOR Benchmarks
Semgrep reports that GLM 5.2, an open-weight model from Zhipu AI, achieved a 39% F1 score on IDOR detection, ahead of Claude Code's 32% in the same benchmark setup. The test highlights how much vulnerability-detection performance depends on the surrounding harness, while Semgrep's own purpose-built pipeline still performed better overall.