$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: CI/CD platform with unauthenticated webhook endpoint that reads arbitrary files via user-controlled filepath parameter (weak path filter). Solution: 3-step chain — arbitrary file read to leak JWT secret from /app/data/.env.secrets, forge admin JWT token, then RCE via admin pipeline execution endpoint that passes commands to child_process.exec().
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar