$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: CI/CD platform with CLI endpoint using args4j expandAtFiles, allowing @-prefixed args to read server files. Solution: chain arbitrary file read to leak JWT signing key, forge admin token, execute shell commands via /api/admin/script.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar