A Python 2 Flask application whose 404 page pastes the requested URL into a Jinja2 template string and renders it.
Not startedDockercommit 6f2863dx86_64 · aarch64Secret
Inject a Jinja2 expression through the URL and escalate it to run a command on the server (server-side template injection).
The brief for this lab lives in its repository.