La Casa de Papel (Secure Comms) — Zer0d4yh31st CTF

A Flask/Jinja2 app renders user-supplied names directly into a template, enabling SSTI that dumps os.environ to leak the flag stored as an environment variable.

June 6, 2026 · 2 min · 214 words · Th3B0yWh0L1v3d