What happened
CodeWall's autonomous agent mapped Lilli's publicly documented API surface, identified 22 unauthenticated endpoints, exploited SQL injection in JSON key names on a search endpoint (bypassing value-parameterization protections), chained with IDOR for account-level access, and achieved unrestricted production database read/write in 15 blind iteration cycles.