A Flask 1.1.1 application that builds a Jinja2 template from the name query parameter, so template expressions in it are evaluated on the server (SSTI), up to running Python and shell commands.
Not startedDockercommit b88eb52x86_64 · aarch64Secret
Exploit the Jinja2 template injection to run commands on the server and read the flag.
The brief for this lab lives in its repository.