Security training for the apps you actually ship. Open your browser and start hacking.
Security training for the apps you actually ship.
36 challenges across web, API, authentication, business logic, cryptography, supply chain, AI agents and MCP.
Break a deliberately vulnerable e-commerce app built on Next.js, React, TypeScript and Prisma.
Find the bugs. Exploit them. Understand why they work.
Docker Hub · npm · Roadmap · Walkthroughs · Contributing · Good first issues
____ ____ ____ ____ ____ ____ _
/ __ \/ __// __/ / __ \ ___ ___ ___ / __/ ___ ____ / __/ / /_ ___ ____ ___
/ /_/ /\ \ _\ \ / /_/ // _ \ / _ \(_-<_\ \ / -_)/ __/_\ \ / __// _ \ / __// -_)
\____/___//___/ \____/ \___// .__/___/___/ \__/ \__//___/ \__/ \___//_/ \__/
/_/
# Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
# Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store
# Then open http://localhost:3000 and start hacking
Click any screenshot to view it full size.
Start the labnpx create-oss-store my-ctf-lab && cd my-ctf-lab && npm startOr run it with Docker. The store comes up on localhost:3000. |
|
|
Go after challenge #1 Public env variable leak: a payment secret that Next.js bakes into the client bundle. Easy · 15–20 min · nothing but your browser devtools. |
|
|
Stuck? Read the walkthrough Every challenge has one, from vulnerability to exploit to fix. The first: Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js. |
|
|
Validate the flag Paste OSS{...} into the flag checker, the floating widget on every page.Your player dashboard tracks what is left. |
|
|
Pick the next one The roadmap orders every challenge across chapters: difficulty, time estimate, prerequisites. Take the next card, then back to step 2. ↻ |
[!TIP] All captured? Join the Hall of Fame, star the repo, and post your route in Show your solve.
New to offensive security? The TryHackMe room wraps the first flags in a guided narrative.
[!WARNING] This application contains intentional security flaws and must never be deployed in a production environment.