
Path Traversal Vulnerability in OopsSec Store's Document API
ctfpath-traversalbroken-access-controlinput-validationmedium
Challenge 8/36 · Broken Access Control. Path traversal in document API. Medium · Input Validation · 30–45 min. Exploiting an unsanitized file path parameter in OopsSec Store's documents API to read files outside the intended directory and retrieve a flag. Spin up the lab: npx create-oss-store my-ctf-lab. See it on the roadmap. Walkthrough — spoilers, read it once you are stuck. Star OopsSec Store on GitHub.