An Express 4.15.5 static file server on Node.js 8.5.0, vulnerable to CVE-2017-14849: path.normalize in Node 8.5.0 mishandles a sequence like /static/../../a/../../../etc/passwd, so send's traversal check is bypassed and any file is read.
Not startedDockercommit 2574baax86_64 · aarch64Secret
Exploit CVE-2017-14849 to read files outside the static folder and read the flag.
The brief for this lab lives in its repository.