$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: FastAPI app renders user templates in a Jinja2 3.1.6 SandboxedEnvironment (unbreakable, all CVEs patched). Solution: the app leaks a live sqlite3.Connection into template globals via a custom `log` logger whose SQLiteHandler exposes a PUBLIC `con` attribute; since the sandbox only blocks underscore-prefixed attributes, log.handlers[0].con.execute(SQL) yields arbitrary SQL and dumps the flag table.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar