webPromedium

Lab 351 — FlowForge — RCE via Python Code Validation Endpoint

hackadvisor

Task: AI workflow platform with Python code validation API endpoint that doesn't require authentication. Solution: Exploited unsafe exec() in validation endpoint using exception-based exfiltration to read flag.

$ ls tags/ techniques/
api_endpoint_enumerationpython_code_injectionexception_based_exfiltrationdecorator_execution_abuse

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups