
CTF challenge exploiting CVE-2025-0184 DOCX SSRF vulnerability to access internal admin service and retrieve a flag. Includes exploit generator and Docker setup.
# 1. Setup and Build
make setup
make build
# 2. Start Services
make up
# 3. Web Access
open http://localhost:8080
Access the internal Admin service (port 3003) and obtain the flag!
Expected Flag: CTF{flag_readme}
cd exploits
python3 exploit_generator.py
# Upload the payloads/admin_flag.docx file via the web
Based on real CVE-2025-0184 vulnerability in langgenius/dify