code
Jan 27, 2026CODE-003Review this Flask API endpoint for security vulnerabilities. Identify ALL security issues and explain the fix for each. ```python from flask import Flask, request, jsonify import sqlite3 import pickle import os app = Flask(__name__) @app.route('/api/user/<user_id>') def get_user(user_id): conn = sqlite3.connect('users.db') cursor = conn.cursor() query = f"SELECT * FROM users WHERE id = {user_id}" cursor.execute(query) user = cursor.fetchone() return jsonify({"user": user}) @app.route('/api/upload', methods=['POST']) def upload_file(): file = request.files['file'] filename = file.filename file.save(os.path.join('/uploads', filename)) return jsonify({"status": "uploaded", "path": f"/uploads/{filename}"}) @app.route('/api/settings', methods=['POST']) def update_settings(): data = pickle.loads(request.data) # Process settings... return jsonify({"status": "updated"}) @app.route('/api/redirect') def redirect_user(): url = request.args.get('url') return f'<meta http-equiv="refresh" content="0;url={url}">' ```
Winner
Claude Opus 4.6
openrouter
9.57
WINNER SCORE
matrix avg: 9.03
10×10 Judgment Matrix · 90 judgments
OPEN DATA
| Judge ↓ / Respondent → | GPT-5.4 | Claude Opus 4.6 | Gemini 3.1 Pro | Claude Sonnet 4.6 | Grok 4.20 | DeepSeek V4 | GPT-OSS-120B | Gemini 3 | MiniMax M2.5 | MiMo-V2-Flash |
|---|---|---|---|---|---|---|---|---|---|---|
| GPT-5.4 | — | 8.6 | 6.5 | 5.0 | 8.2 | 8.2 | 8.2 | 8.2 | 7.5 | 7.8 |
| Claude Opus 4.6 | 9.2 | — | 8.8 | 9.0 | 9.3 | 9.2 | 9.0 | 9.3 | 9.0 | 9.2 |
| Gemini 3.1 Pro | 9.3 | 10.0 | — | 7.9 | 10.0 | 9.3 | 8.1 | 10.0 | 8.8 | 7.8 |
| Claude Sonnet 4.6 | 9.8 | 9.8 | 9.6 | — | 9.3 | 8.8 | 9.2 | 9.0 | 8.6 | 9.0 |
| Grok 4.20 | 9.2 | 9.2 | 8.6 | 9.0 | — | 8.8 | 9.0 | 8.8 | 8.8 | 8.8 |
| DeepSeek V4 | 9.6 | 9.8 | 9.6 | 9.8 | 9.6 | — | 9.4 | 9.6 | 9.6 | 9.6 |
| GPT-OSS-120B | 8.6 | 9.0 | 8.1 | 7.5 | 8.6 | 8.6 | — | 8.6 | 8.6 | 9.0 |
| Gemini 3 | 10.0 | 10.0 | 9.8 | 9.6 | 9.8 | 9.8 | 10.0 | — | 9.8 | 9.8 |
| MiniMax M2.5 | 10.0 | 9.8 | 8.6 | 7.7 | 9.0 | 9.6 | 9.0 | 9.6 | — | 9.4 |
| MiMo-V2-Flash | 9.3 | 10.0 | 8.6 | 9.0 | 9.3 | 8.8 | 9.3 | 10.0 | 9.0 | — |