boroGPT
Source-map leak reveals JWT secret, forge admin token, then exploit Jinja2 SSTI for RCE.
No writeups match your filter.
Source-map leak reveals JWT secret, forge admin token, then exploit Jinja2 SSTI for RCE.
A Flask/Jinja2 app renders user-supplied names directly into a template, enabling SSTI that dumps os.environ to leak the flag stored as an environment variable.