アップデート一覧に戻る
New releaseAug 12, 2026

oss-oopssec-store v2.18.0

実際に出荷するアプリのためのセキュリティトレーニング。ブラウザを開いてハッキングを始めましょう。

共有

OSS - OopsSec Store

実際に出荷するアプリのためのセキュリティトレーニング。

Web、API、認証、ビジネスロジック、暗号技術、サプライチェーン、AIエージェント、MCPにわたる36のチャレンジ。

Next.js、React、TypeScript、Prismaで構築された、意図的に脆弱なEコマースアプリを攻略せよ。
バグを見つけ、悪用し、なぜそれが機能するのかを理解する。

Docker Hub · npm · ロードマップ · ウォークスルー · コントリビューション · 初心者向けIssue

OWASP VWAD TryHackMe room Intentionally Vulnerable
GitHub license PRs Welcome Good first issues
GitHub stars GitHub forks

```bash

/ __ / // / / __ \ ___ ___ ___ / / ___ ____ / / / / ___ ____ ___ / // /\ \ \ \ / // // _ \ / _ (-<\ \ / -)/ __/\ \ / // _ \ / // -) _//// __/ _// ./// _/ _/// _/ ___/// _/ /_/

Start with Node.js

npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start

Start with Docker

docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store

Then open http://localhost:3000 and start hacking

<div align="center">

<table>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-0.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-0.png" alt="OopsSec Store storefront" width="100%"></a>
<br><sub><b>Storefront</b> · あなたが攻撃する e コマースアプリ</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-1.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-1.png" alt="Player dashboard tracking captured flags" width="100%"></a>
<br><sub><b>プレイヤーダッシュボード</b> · 進捗、難易度、カテゴリ別の内訳</sub>
</td>
</tr>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-2.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-2.png" alt="OSSBot AI customer support assistant" width="100%"></a>
<br><sub><b>OSSBot</b> · あなたがプロンプトインジェクションする AI サポートアシスタント</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-3.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-3.png" alt="Challenge roadmap across 11 chapters" width="100%"></a>
<br><sub><b>ロードマップ</b> · 本番コードに紛れ込むバグたち</sub>
</td>
</tr>
</table>

<sub>スクリーンショットをクリックすると拡大表示されます。</sub>

</div>

---

## はじめに

<table>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/1-15803d?style=for-the-badge" alt="Step 1"></td>
<td valign="top">
<b>ラボを起動する</b><br>
<code>npx create-oss-store my-ctf-lab &amp;&amp; cd my-ctf-lab &amp;&amp; npm start</code><br>
<sub>または <a href="#docker">Docker で実行する</a>。ストアは <a href="http://localhost:3000">localhost:3000</a> で起動します。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/2-15803d?style=for-the-badge" alt="Step 2"></td>
<td valign="top">
<b>チャレンジ #1 に挑む</b><br>
<a href="http://localhost:3000/vulnerabilities/public-env-variable">公開環境変数の漏洩</a>: Next.js がクライアントバンドルに埋め込んでしまう決済シークレット。<br>
<sub>Easy · 15〜20 分 · 必要なのはブラウザの devtools だけ。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/3-15803d?style=for-the-badge" alt="Step 3"></td>
<td valign="top">
<b>詰まったら? ウォークスルーを読む</b><br>
すべてのチャレンジに用意されています。脆弱性からエクスプロイト、修正まで。<br>
<sub>最初の一本: <a href="https://koadt.github.io/oss-oopssec-store/posts/next-public-env-variable-leak/">Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js</a>。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/4-15803d?style=for-the-badge" alt="Step 4"></td>
<td valign="top">
<b>フラグを検証する</b><br>
<code>OSS{...}</code> をフラグチェッカーに貼り付けます。これはすべてのページに浮かんでいるウィジェットです。<br>
<sub><a href="http://localhost:3000/player-dashboard">プレイヤーダッシュボード</a>が残りを追跡します。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/5-15803d?style=for-the-badge" alt="Step 5"></td>
<td valign="top">
<b>次の一本を選ぶ</b><br>
<a href="https://koadt.github.io/oss-oopssec-store/roadmap">ロードマップ</a>がすべてのチャレンジを章ごとに整理しています: 難易度、所要時間の目安、前提条件。<br>
<sub>次のカードを取って、ステップ 2 に戻る。 ↻</sub>
</td>
</tr>
</table>

> [!TIP]
> すべて攻略しましたか? [Hall of Fame に参加](#hall-of-fame)し、リポジトリにスターを付け、[Show your solve](https://github.com/kOaDT/oss-oopssec-store/discussions/categories/show-your-solve) にあなたのルートを投稿してください。

<sub>オフェンシブセキュリティは初めてですか? <a href="https://tryhackme.com/jr/oopssecstorethesummeraudit">TryHackMe ルーム</a>では、最初のフラグをガイド付きのストーリーで体験できます。</sub>

---

## 目次

- [機能](#features)
- [なぜ OopsSec Store なのか?](#why-oopssec-store)
- [インストール](#installation)
  - [クイックスタート (npm)](#quick-start)
  - [Docker](#docker)
- [Hall of fame](#hall-of-fame)
- [コミュニティ](#community)
- [プロジェクト構成](#project-structure)
- [テスト](#testing)
- [免責事項](#disclaimer)
- [コントリビューション](#contributing)
- [Educator Kit](#-using-oopssec-store-in-a-course-or-ctf)
- [プロジェクト統計](#project-stats)

---

> [!WARNING]
> このアプリケーションには意図的なセキュリティ上の欠陥が含まれています。本番環境にデプロイしてはいけません。

## 機能

- 意図的に脆弱な e コマースアプリ (XSS、CSRF、IDOR、JWT 攻撃、パストラバーサル、SQL インジェクションなど)
- Next.js (App Router)、React、TypeScript、Prisma、SQLite で構築
- 攻撃ベクトルを文書化した REST API
- 11 章にわたる 36 の CTF チャレンジ。体系的な[学習ロードマップ](https://koadt.github.io/oss-oopssec-store/roadmap)として構成
- 各チャレンジの脆弱性ドキュメントとコミュニティによるウォークスルー
- ガイド付きの [TryHackMe ルーム](https://tryhackme.com/jr/oopssecstorethesummeraudit): _The Summer Audit_、8 タスクと 7 フラグ。初心者向けのストーリー形式の入門編
- エクスプロイトが今も機能することを検証する自動テスト (誤って脆弱性を修正してしまった PR は CI で失敗します)

## なぜ OopsSec Store なのか?

モダンなフレームワークは、セキュリティ脆弱性が現れる場所と、その修正方法を変えました。OopsSec Store は、古典的な脆弱性クラスを、今日多くの開発者が使うスタックに落とし込みます: Next.js App Router、React、TypeScript、Prisma です。

サーバーレンダリングコンポーネント、ミドルウェア、ORM は、異なる信頼境界と障害モードを持ち込みます。いくつかのチャレンジは、このスタックに対する公開済みの CVE も再現しています。

カリキュラムは、AI 支援開発とともに登場した攻撃対象領域もカバーしています: カスタマーサポートエージェントに対するプロンプトインジェクション、MCP ツールポイズニング、バックドア入りのコーディングエージェントルールファイル、そして npm タイポスクワットチェーンのエンドツーエンドシミュレーションです。

カテゴリ