
oss-oopssec-store v2.20.0
Security training for the apps you actually ship. Open your browser and start hacking.
OSS - OopsSec Store
Security training for the apps you actually ship.
36 challenges across web, API, authentication, business logic, cryptography, supply chain, AI agents and MCP.
Break a deliberately vulnerable e-commerce app built on Next.js, React, TypeScript and Prisma.
Find the bugs. Exploit them. Understand why they work.
Docker Hub · npm · Roadmap · Walkthroughs · Contributing · Good first issues
____ ____ ____ ____ ____ ____ _
/ __ \/ __// __/ / __ \ ___ ___ ___ / __/ ___ ____ / __/ / /_ ___ ____ ___
/ /_/ /\ \ _\ \ / /_/ // _ \ / _ \(_-<_\ \ / -_)/ __/_\ \ / __// _ \ / __// -_)
\____/___//___/ \____/ \___// .__/___/___/ \__/ \__//___/ \__/ \___//_/ \__/
/_/
# Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
# Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store
# Then open http://localhost:3000 and start hacking
Click any screenshot to view it full size.
Getting started
Start the labnpx create-oss-store my-ctf-lab && cd my-ctf-lab && npm startOr run it with Docker. The store comes up on localhost:3000. |
|
|
Go after challenge #1 Public env variable leak: a payment secret that Next.js bakes into the client bundle. Easy · 15–20 min · nothing but your browser devtools. |
|
|
Stuck? Read the walkthrough Every challenge has one, from vulnerability to exploit to fix. The first: Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js. |
|
|
Validate the flag Paste OSS{...} into the flag checker, the floating widget on every page.Your player dashboard tracks what is left. |
|
|
Pick the next one The roadmap orders every challenge across chapters: difficulty, time estimate, prerequisites. Take the next card, then back to step 2. ↻ |
[!TIP] All captured? Join the Hall of Fame, star the repo, and post your route in Show your solve.
New to offensive security? The TryHackMe room wraps the first flags in a guided narrative.
Table of contents
- Features
- Why OopsSec Store?
- Installation
- Hall of fame
- Community
- Project structure
- Testing
- Disclaimer
- Contributing
- Educator Kit
- Project stats
[!WARNING] This application contains intentional security flaws and must never be deployed in a production environment.



