$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask app with GraphQL API where hidden queries exist beyond what the UI exposes. Solution: discover /graphql endpoint from client JS, use introspection to enumerate schema, find hidden getFlag query, call it with isAdmin: true.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar