$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: NPM package registry (PackForge) with publish API and EJS README rendering; debug mode leaks internal paths. Solution: path traversal in scoped package name writes malicious EJS template to templates directory, then render-readme endpoint triggers SSTI for RCE.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar