Approve Please, Genie!
CSS injection and browser side-channel exfiltration leak the flag from the approval bot.
CSS injection and browser side-channel exfiltration leak the flag from the approval bot.
Vite CVE-2025-30208 bypasses the dev server allow list and exposes arbitrary files through /@fs/.
DOM Clobbering bypasses the sanitizer and enables file-name disclosure followed by flag read.
Client-side privilege escalation and SQL injection lead to the administrator account and flag.
Double URL encoding bypasses an absolute-path filter and enables local file read.
Path traversal in the mod build flow writes a Python codec payload and reaches server-side code execution.
Jinja2 SSTI bypasses a blacklist, reaches RCE, and reads the challenge flag.
CTF writeup - web/Ganzir (OmniCTF 2026)
CTF writeup - web/StayWild (OmniCTF 2026)
CTF writeup - web_<_w+ (SekaiCTF 2026)
CTF writeup - web/migurimental (SekaiCTF 2026)
CTF writeup - cookoff (GPNCTF 2026)
CTF writeup - Fancy Food Notifications (GPNCTF 2026)
CTF writeup - Pharry (GPNCTF 2026)
CTF writeup - recipeloader (GPNCTF 2026)
CTF writeup - restaurant-builder (GPNCTF 2026)
CTF writeup - SecretPickle (GPNCTF 2026)
CTF writeup - Secure Secretpickle (GPNCTF 2026)
CTF writeup - Simple food notifications (GPNCTF 2026)
CTF writeup - web/chained (TJCTF 2026)
CTF writeup - web/free-cloud-storage (TJCTF 2026)
CTF writeup - web/paper-trail (TJCTF 2026)
CTF writeup - web/treasure-hunt (TJCTF 2026)
CTF writeup - web/Vibed Intranet Part 1&2 (TJCTF 2026)
CTF writeup - web/vibecoded (TJCTF 2026)
CTF writeup - Brick by Brick (UMassCTF 2026)
CTF writeup - BrOWSER BOSS FIGHT (UMassCTF 2026)
CTF writeup - ORDER66 (UMassCTF 2026)
CTF writeup - Break the Bank (UTCTF 2026)
CTF writeup - Crab Mentality (UTCTF 2026)
CTF writeup - Time to Pretend (UTCTF 2026)