$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Express.js notification platform with template preview endpoint using JavaScript Function constructor for server-side template literal evaluation. Solution: SSTI via ${} expressions in POST /api/templates/preview, escalated to process.env disclosure via ${JSON.stringify(process.env)} to extract FLAG from environment variables.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar