$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a Flask/Werkzeug SVG-to-PNG converter accepted raw XML and stored the rendered image at /static/data.png. Solution: exploit XXE in the SVG parser to load file:///flag.txt, render the file contents inside the generated PNG, and verify the result with repeated OCR after correcting an initial xmi/xml misread.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar