404CTF 2026 - Le Wiki d'Hélène Metzger
TL;DR: RCE through polluting node execSync options and algorithm confusion
TL;DR: RCE through polluting node execSync options and algorithm confusion
TL;DR: XSS via HTML entity double-parse and CSP bypass via PHP warning
TL;DR: SSRF by bypassing the https:// scheme filter through an XML parsing discrepancy
TL;DR: RCE via data: URI injection in import() and node permission bypass via inspector API
TL;DR: XSS via path traversal chained with arbitrary file write through PHP session upload progress