$ cat writeup.md…
$ cat writeup.md…
kalmarctf
Task: Forgejo provisions a personal repository and stores the flag as an Actions secret. Solution: abuse shell injection in `${{ github.head_ref }}` under `pull_request_target`, poison `GITHUB_OUTPUT`, and turn a later `cp -r` step into a secret leak.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar