$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: TeamVault workspace management platform with GraphQL API where temporary members are restricted from admin resources. Solution: GraphQL introspection reveals updateMemberAccess mutation lacking authorization checks, allowing any authenticated user to set their own isPermanent to true and access the Secrets Vault containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar