
New releaseSep 10, 2026
oss-oopssec-store v2.20.0
実際に出荷するアプリのためのセキュリティトレーニング。ブラウザを開いてハッキングを始めましょう。
OSS - OopsSec Store
実際に出荷するアプリのためのセキュリティトレーニング。
Web、API、認証、ビジネスロジック、暗号技術、サプライチェーン、AIエージェント、MCPにわたる36のチャレンジ。
Next.js、React、TypeScript、Prismaで構築された、意図的に脆弱なEコマースアプリを攻略せよ。
バグを見つけ、悪用し、なぜそれが機能するのかを理解する。
Docker Hub · npm · ロードマップ · ウォークスルー · コントリビューション · 初心者向けIssue
/ __ / // / / __ \ ___ ___ ___ / / ___ ____ / / / / ___ ____ ___ / // /\ \ \ \ / // // _ \ / _ (-<\ \ / -)/ __/\ \ / // _ \ / // -) _//// __/ _// ./// _/ _/// _/ ___/// _/ /_/
Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store
Then open http://localhost:3000 and start hacking
<div align="center">
<table>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-0.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-0.png" alt="OopsSec Store storefront" width="100%"></a>
<br><sub><b>Storefront</b> · あなたが攻撃する e コマースアプリ</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-1.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-1.png" alt="Player dashboard tracking captured flags" width="100%"></a>
<br><sub><b>プレイヤーダッシュボード</b> · 進捗、難易度、カテゴリ別の内訳</sub>
</td>
</tr>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-2.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-2.png" alt="OSSBot AI customer support assistant" width="100%"></a>
<br><sub><b>OSSBot</b> · あなたがプロンプトインジェクションする AI サポートアシスタント</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-3.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-3.png" alt="Challenge roadmap across 11 chapters" width="100%"></a>
<br><sub><b>ロードマップ</b> · 本番コードに紛れ込むバグたち</sub>
</td>
</tr>
</table>
<sub>スクリーンショットをクリックすると拡大表示されます。</sub>
</div>
---
## はじめに
<table>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/1-15803d?style=for-the-badge" alt="Step 1"></td>
<td valign="top">
<b>ラボを起動する</b><br>
<code>npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start</code><br>
<sub>または <a href="#docker">Docker で実行する</a>。ストアは <a href="http://localhost:3000">localhost:3000</a> で起動します。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/2-15803d?style=for-the-badge" alt="Step 2"></td>
<td valign="top">
<b>チャレンジ #1 に挑む</b><br>
<a href="http://localhost:3000/vulnerabilities/public-env-variable">公開環境変数の漏洩</a>: Next.js がクライアントバンドルに埋め込んでしまう決済シークレット。<br>
<sub>Easy · 15〜20 分 · 必要なのはブラウザの devtools だけ。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/3-15803d?style=for-the-badge" alt="Step 3"></td>
<td valign="top">
<b>詰まったら? ウォークスルーを読む</b><br>
すべてのチャレンジに用意されています。脆弱性からエクスプロイト、修正まで。<br>
<sub>最初の一本: <a href="https://koadt.github.io/oss-oopssec-store/posts/next-public-env-variable-leak/">Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js</a>。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/4-15803d?style=for-the-badge" alt="Step 4"></td>
<td valign="top">
<b>フラグを検証する</b><br>
<code>OSS{...}</code> をフラグチェッカーに貼り付けます。これはすべてのページに浮かんでいるウィジェットです。<br>
<sub><a href="http://localhost:3000/player-dashboard">プレイヤーダッシュボード</a>が残りを追跡します。</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/5-15803d?style=for-the-badge" alt="Step 5"></td>
<td valign="top">
<b>次の一本を選ぶ</b><br>
<a href="https://koadt.github.io/oss-oopssec-store/roadmap">ロードマップ</a>がすべてのチャレンジを章ごとに整理しています: 難易度、所要時間の目安、前提条件。<br>
<sub>次のカードを取って、ステップ 2 に戻る。 ↻</sub>
</td>
</tr>
</table>
> [!TIP]
> すべて攻略しましたか? [Hall of Fame に参加](#hall-of-fame)し、リポジトリにスターを付け、[Show your solve](https://github.com/kOaDT/oss-oopssec-store/discussions/categories/show-your-solve) にあなたのルートを投稿してください。
<sub>オフェンシブセキュリティは初めてですか? <a href="https://tryhackme.com/jr/oopssecstorethesummeraudit">TryHackMe ルーム</a>では、最初のフラグをガイド付きのストーリーで体験できます。</sub>
---
## 目次
- [機能](#features)
- [なぜ OopsSec Store なのか?](#why-oopssec-store)
- [インストール](#installation)
- [クイックスタート (npm)](#quick-start)
- [Docker](#docker)
- [Hall of fame](#hall-of-fame)
- [コミュニティ](#community)
- [プロジェクト構成](#project-structure)
- [テスト](#testing)
- [免責事項](#disclaimer)
- [コントリビューション](#contributing)
- [Educator Kit](#-using-oopssec-store-in-a-course-or-ctf)
- [プロジェクト統計](#project-stats)
---
> [!WARNING]
> このアプリケーションには意図的なセキュリティ上の欠陥が含まれています。本番環境にデプロイしてはいけません。
## 機能
- 意図的に脆弱な e コマースアプリ (XSS、CSRF、IDOR、JWT 攻撃、パストラバーサル、SQL インジェクションなど)
- Next.js (App Router)、React、TypeScript、Prisma、SQLite で構築
- 攻撃ベクトルを文書化した REST API
- 11 章にわたる 36 の CTF チャレンジ。体系的な[学習ロードマップ](https://koadt.github.io/oss-oopssec-store/roadmap)として構成
- 各チャレンジの脆弱性ドキュメントとコミュニティによるウォークスルー
- ガイド付きの [TryHackMe ルーム](https://tryhackme.com/jr/oopssecstorethesummeraudit): _The Summer Audit_、8 タスクと 7 フラグ。初心者向けのストーリー形式の入門編
- エクスプロイトが今も機能することを検証する自動テスト (誤って脆弱性を修正してしまった PR は CI で失敗します)
## なぜ OopsSec Store なのか?
モダンなフレームワークは、セキュリティ脆弱性が現れる場所と、その修正方法を変えました。OopsSec Store は、古典的な脆弱性クラスを、今日多くの開発者が使うスタックに落とし込みます: Next.js App Router、React、TypeScript、Prisma です。
サーバーレンダリングコンポーネント、ミドルウェア、ORM は、異なる信頼境界と障害モードを持ち込みます。いくつかのチャレンジは、このスタックに対する公開済みの CVE も再現しています。
カリキュラムは、AI 支援開発とともに登場した攻撃対象領域もカバーしています: カスタマーサポートエージェントに対するプロンプトインジェクション、MCP ツールポイズニング、バックドア入りのコーディングエージェントルールファイル、そして npm タイポスクワットチェーンのエンドツーエンドシミュレーションです。