$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a FastAPI preview endpoint rendered attacker-controlled Jinja2 templates inside SandboxedEnvironment with a live Pydantic user object in context. Solution: abuse exposed BaseModel.parse_raw(..., content_type=\"application/pickle\", allow_pickle=True) to deserialize a malicious pickle, gain RCE, and read the flag file.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar