The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A backup file left in the web root
Find the secret the application leaks without meaning to.
A login that leaks which half was wrong
Get past the login without the credential it is supposed to demand.
A negative quantity at checkout
Use the feature exactly as built, in an order it never anticipated.
A price that travels in the request
Use the feature exactly as built, in an order it never anticipated.
A quote that breaks the login query
Break out of a query or a shell command through unescaped input.
Changing an email with a single GET
Make a logged-in victim's browser send a state-changing request.
Comments in the source with a key in them
Find the secret the application leaks without meaning to.
Reading another user's support tickets
Reach an object that was never yours by changing the id that names it.
Reflected in the search box
Get your script to run in another visitor's browser on this origin.
The default credential nobody changed
Get past the login without the credential it is supposed to demand.
The error page that echoes your input
Get your script to run in another visitor's browser on this origin.
The invoice with your neighbour's name on it
Reach an object that was never yours by changing the id that names it.
The order history one id away
Reach an object that was never yours by changing the id that names it.
The search filter that trusts your input
Break out of a query or a shell command through unescaped input.
The stack trace that names the database
Find the secret the application leaks without meaning to.
A CNAME pointing at a deleted bucket
Claim a dangling DNS record that points at an unclaimed host.
A comment field that renders markdown too eagerly
Get your script to run in another visitor's browser on this origin.
A hidden form value that grants admin
Climb from the access you were given to access you were not.
A JSON endpoint that accepts form content-type
Make a logged-in victim's browser send a state-changing request.
A password-reset token you can predict
Break the guarantee a weak or misused primitive was meant to give.
A serialized cart the client can edit
Feed the server a serialized object it will trust and rebuild.
A webhook tester pointed at localhost
Make the server fetch a URL of your choosing, from inside its network.
An ECB-mode image that leaks its shape
Break the guarantee a weak or misused primitive was meant to give.
An image importer aimed inward
Make the server fetch a URL of your choosing, from inside its network.
Applying the same coupon twice
Use the feature exactly as built, in an order it never anticipated.
Breaking out of an HTML attribute
Get your script to run in another visitor's browser on this origin.
Deleting a comment you did not write
Reach an object that was never yours by changing the id that names it.
Editing a profile that is not yours
Reach an object that was never yours by changing the id that names it.
Error-based extraction from a chatty endpoint
Break out of a query or a shell command through unescaped input.
Redeeming a one-time code twice
Slip through the window between a check and the action it guards.
Registering the same username twice
Slip through the window between a check and the action it guards.
Secrets committed to an exposed .git
Find the secret the application leaks without meaning to.
Skipping the second step of a two-step login
Get past the login without the credential it is supposed to demand.
Stored in a display name
Get your script to run in another visitor's browser on this origin.
The debug endpoint still answering in production
Find the secret the application leaks without meaning to.
The export endpoint that forgot to ask who is asking
Reach an object that was never yours by changing the id that names it.
The form with no anti-forgery token
Make a logged-in victim's browser send a state-changing request.
The link-preview that fetches anything
Make the server fetch a URL of your choosing, from inside its network.
The pages site that was never published
Claim a dangling DNS record that points at an unclaimed host.
The remember-me cookie that means too much
Get past the login without the credential it is supposed to demand.
The role field the client should not set
Climb from the access you were given to access you were not.
The role hidden in a base64 cookie
Feed the server a serialized object it will trust and rebuild.
UNION-selecting the users table
Break out of a query or a shell command through unescaped input.
User enumeration through timing
Find the secret the application leaks without meaning to.
Voting more than once by replaying the request
Use the feature exactly as built, in an order it never anticipated.
A file type check you can talk past
Turn a foothold into commands running on the server itself.
A GUID is not an authorization check
Reach an object that was never yours by changing the id that names it.
A length-extension against a naive MAC
Break the guarantee a weak or misused primitive was meant to give.
A password reset that trusts the wrong field
Get past the login without the credential it is supposed to demand.
An admin route that never re-checks
Climb from the access you were given to access you were not.
An API version that forgot to retire
Find the secret the application leaks without meaning to.
An expired CDN configuration still referenced
Claim a dangling DNS record that points at an unclaimed host.
An invite flow that leaks a higher role
Climb from the access you were given to access you were not.
An OAuth state parameter nobody validates
Get past the login without the credential it is supposed to demand.
An upload that lands in an executable path
Turn a foothold into commands running on the server itself.
Applying two coupons in the same instant
Slip through the window between a check and the action it guards.
Approving your own request as its reviewer
Climb from the access you were given to access you were not.
Beating a rate limit with concurrency
Slip through the window between a check and the action it guards.
Blind SSRF confirmed out of band
Make the server fetch a URL of your choosing, from inside its network.
Boolean-blind, one bit at a time
Break out of a query or a shell command through unescaped input.
Bypassing an allowlist with a DNS trick
Make the server fetch a URL of your choosing, from inside its network.
Defeating a predictable token
Make a logged-in victim's browser send a state-changing request.
DOM XSS through the URL fragment
Get your script to run in another visitor's browser on this origin.
GraphQL introspection left switched on
Find the secret the application leaks without meaning to.
Injecting into a JSON block the page evaluates
Get your script to run in another visitor's browser on this origin.
Mass-assigning your way into an admin group
Reach an object that was never yours by changing the id that names it.
Metadata in an uploaded file's response
Find the secret the application leaks without meaning to.
Reaching the cloud metadata endpoint
Make the server fetch a URL of your choosing, from inside its network.
Referral rewards that pay you to invite yourself
Use the feature exactly as built, in an order it never anticipated.
Reusing a magic link that never expired
Get past the login without the credential it is supposed to demand.
SameSite is not set, and it matters
Make a logged-in victim's browser send a state-changing request.
Second-order injection through a stored value
Break out of a query or a shell command through unescaped input.
Skipping the payment step of the order
Use the feature exactly as built, in an order it never anticipated.
Slipping past a naive filter
Get your script to run in another visitor's browser on this origin.
Swapping a JWT to the 'none' algorithm
Break the guarantee a weak or misused primitive was meant to give.
Tampering with a signed-but-unverified token
Feed the server a serialized object it will trust and rebuild.
The cancelled SaaS that left a dangling record
Claim a dangling DNS record that points at an unclaimed host.
The JWT signed with a guessable secret
Break the guarantee a weak or misused primitive was meant to give.
The nested resource that skipped its parent's check
Reach an object that was never yours by changing the id that names it.
Time-based extraction from a silent endpoint
Break out of a query or a shell command through unescaped input.
Type confusion in a rebuilt object
Feed the server a serialized object it will trust and rebuild.
Upgrading a plan without paying the difference
Use the feature exactly as built, in an order it never anticipated.
Withdrawing a balance in parallel
Slip through the window between a check and the action it guards.
A dependency confusion package that runs on install
Turn a foothold into commands running on the server itself.
A gadget chain to state change
Feed the server a serialized object it will trust and rebuild.
A padding oracle that reads the ciphertext
Break the guarantee a weak or misused primitive was meant to give.
A support-impersonation feature turned on yourself
Climb from the access you were given to access you were not.
A TOCTOU gap in a file upload
Slip through the window between a check and the action it guards.
Argument injection into a called binary
Turn a foothold into commands running on the server itself.
Assembling a discount no single rule forbids
Use the feature exactly as built, in an order it never anticipated.
Chaining a takeover into cookie theft
Claim a dangling DNS record that points at an unclaimed host.
Chaining two objects into a full account read
Reach an object that was never yours by changing the id that names it.
Command injection through a filename
Break out of a query or a shell command through unescaped input.
Double-spend across two endpoints at once
Slip through the window between a check and the action it guards.
Forging a session from a leaked signing key
Break the guarantee a weak or misused primitive was meant to give.
Forging the 'already verified' state
Get past the login without the credential it is supposed to demand.
From deserialization gadget to shell
Turn a foothold into commands running on the server itself.
From deserialization to file write
Feed the server a serialized object it will trust and rebuild.
Gopher-smuggling a request to an internal service
Make the server fetch a URL of your choosing, from inside its network.
Horizontal to vertical in two steps
Climb from the access you were given to access you were not.
Inheriting permissions through a group you joined
Climb from the access you were given to access you were not.
Login CSRF into an attacker's account
Make a logged-in victim's browser send a state-changing request.
Mutation XSS the sanitiser did not expect
Get your script to run in another visitor's browser on this origin.
Nonce reuse that unwinds the keystream
Break the guarantee a weak or misused primitive was meant to give.
Reading files through the database engine
Break out of a query or a shell command through unescaped input.
Redirect-hopping into a private range
Make the server fetch a URL of your choosing, from inside its network.
Refunding more than you paid
Use the feature exactly as built, in an order it never anticipated.
Stacking queries to write, not just read
Break out of a query or a shell command through unescaped input.
Stealing a session under a weak CSP
Get your script to run in another visitor's browser on this origin.
Template injection to command execution
Turn a foothold into commands running on the server itself.
XXE escalated to a file read and beyond
Turn a foothold into commands running on the server itself.