OWASP Node.js Goat

OWASP Node.js Goat - An OWASP incubator project

About OWASP Node.js Goat

About OWASP NodeGoat

Being lightweight, fast, and scalable, Node.js is becoming a widely adopted platform for developing web applications. This project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

Getting Started

The source code for the OWASP NodeGoat Project is located at Github Repo. You can use it in a couple of ways:

Hands-on Lab

Set up your own copy of the app to fix and test vulnerabilities.

Contributors

Here are the amazing contributors to the NodeGoat project.

License

Code licensed under the Apache License v2.0.

Project Information

Incubator Project
Classification
Incubator
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.