$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Node.js/Express app with custom Storage class and JWT authentication, need to access admin panel. Solution: Prototype Pollution via __proto__ key in merge function to set isAdmin=true and bypass authentication check.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar