$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: GraphQL API management platform with broken authentication — API key leaked in client-side JS, introspection enabled, and createUser mutation allows mass assignment of admin role. Solution: Extract API key from /js/playground.js, enumerate schema via introspection, create admin user via mass assignment on createUser mutation, query adminSettings for the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar