The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A password reset that trusts the wrong field
Get past the login without the credential it is supposed to demand.
An API version that forgot to retire
Find the secret the application leaks without meaning to.
An OAuth state parameter nobody validates
Get past the login without the credential it is supposed to demand.
Defeating a predictable token
Make a logged-in victim's browser send a state-changing request.
DOM XSS through the URL fragment
Get your script to run in another visitor's browser on this origin.
GraphQL introspection left switched on
Find the secret the application leaks without meaning to.
Injecting into a JSON block the page evaluates
Get your script to run in another visitor's browser on this origin.
Metadata in an uploaded file's response
Find the secret the application leaks without meaning to.
Reusing a magic link that never expired
Get past the login without the credential it is supposed to demand.
SameSite is not set, and it matters
Make a logged-in victim's browser send a state-changing request.
Slipping past a naive filter
Get your script to run in another visitor's browser on this origin.