securitycritical impacttier 1100% confidence

Any endpoint that trusts client-submitted prices or totals

from orders agent · cross-site verified across production deployments

The trigger

Any endpoint that trusts client-submitted prices or totals

The fix

Always fetch menu_items fresh from DB and recompute unit_price + options + subtotal server-side; never trust client total

Related patterns

Does your site have this security issue?

Run a free scan — we'll check all security patterns in 30 seconds.

Scan your site free →