PTITCTF Quals 2026
Approve Please, Genie!
CSS injection and browser side-channel exfiltration leak the flag from the approval bot.
Read
CSS injection and browser side-channel exfiltration leak the flag from the approval bot.
Vite CVE-2025-30208 bypasses the dev server allow list and exposes arbitrary files through /@fs/.
DOM Clobbering bypasses the sanitizer and enables file-name disclosure followed by flag read.
Client-side privilege escalation and SQL injection lead to the administrator account and flag.
Double URL encoding bypasses an absolute-path filter and enables local file read.
Path traversal in the mod build flow writes a Python codec payload and reaches server-side code execution.
Jinja2 SSTI bypasses a blacklist, reaches RCE, and reads the challenge flag.