
Public Environment Variable Leak in OopsSec Store - Information Disclosure Challenge
CybersecurityHackingWebVulnerabilitiesInformationDisclosureEnvironmentVariablesCTF
Challenge 1/35 · Reconnaissance & Disclosure. Public env variable leak. Easy · Information Disclosure · 15–20 min. Exploiting a misused NEXT_PUBLIC_ environment variable in OopsSec Store to recover a payment secret embedded in the client JavaScript bundle. Spin up the lab: npx create-oss-store my-ctf-lab. See it on the roadmap. Walkthrough — spoilers, read it once you are stuck. Star OopsSec Store on GitHub.