Back to updates
New releaseSep 10, 2026

oss-oopssec-store v2.20.0

Security training for the apps you actually ship. Open your browser and start hacking.

Share

OSS - OopsSec Store

Security training for the apps you actually ship.

36 challenges across web, API, authentication, business logic, cryptography, supply chain, AI agents and MCP.

Break a deliberately vulnerable e-commerce app built on Next.js, React, TypeScript and Prisma.
Find the bugs. Exploit them. Understand why they work.

Docker Hub · npm · Roadmap · Walkthroughs · Contributing · Good first issues

OWASP VWAD TryHackMe room Intentionally Vulnerable
GitHub license PRs Welcome Good first issues
GitHub stars GitHub forks


   ____  ____ ____     ____                  ____            ____  _
  / __ \/ __// __/    / __ \ ___   ___  ___ / __/ ___  ____ / __/ / /_ ___   ____ ___
 / /_/ /\ \ _\ \     / /_/ // _ \ / _ \(_-<_\ \  / -_)/ __/_\ \  / __// _ \ / __// -_)
 \____/___//___/     \____/ \___// .__/___/___/  \__/ \__//___/  \__/ \___//_/   \__/
                                /_/

# Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start

# Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store

# Then open http://localhost:3000 and start hacking
OopsSec Store storefront
Storefront · the e-commerce app you are attacking
Player dashboard tracking captured flags
Player dashboard · progress, difficulty and category breakdown
OSSBot AI customer support assistant
OSSBot · the AI support assistant you prompt-inject
Challenge roadmap across 11 chapters
Roadmap · the bugs that ship in production code

Click any screenshot to view it full size.


Getting started

Step 1 Start the lab
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
Or run it with Docker. The store comes up on localhost:3000.
Step 2 Go after challenge #1
Public env variable leak: a payment secret that Next.js bakes into the client bundle.
Easy · 15–20 min · nothing but your browser devtools.
Step 3 Stuck? Read the walkthrough
Every challenge has one, from vulnerability to exploit to fix.
The first: Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js.
Step 4 Validate the flag
Paste OSS{...} into the flag checker, the floating widget on every page.
Your player dashboard tracks what is left.
Step 5 Pick the next one
The roadmap orders every challenge across chapters: difficulty, time estimate, prerequisites.
Take the next card, then back to step 2. ↻

[!TIP] All captured? Join the Hall of Fame, star the repo, and post your route in Show your solve.

New to offensive security? The TryHackMe room wraps the first flags in a guided narrative.


Table of contents


[!WARNING] This application contains intentional security flaws and must never be deployed in a production environment.

Features

Categories