Secure Secretpickle — GPN CTF 2026

The hardened secretpickle runs pickle.loads in a write-only seccomp sandbox, but the adminbot action visits an attacker URL with no scheme check and returns a screenshot, so file:///flag.txt renders the flag into the image.

June 6, 2026 · 3 min · 460 words · Th3B0yWh0L1v3d