A Flask 1.1.1 application on Python 3.6 that reads the user cookie, base64-decodes it and unpickles it to get the user name: a pickle whose __reduce__ returns os.system (or similar) runs commands on the server.
Not startedDockercommit ccd5519x86_64 · aarch64Secret
Craft a malicious pickle in the user cookie to run commands on the server and get a shell.
The brief for this lab lives in its repository.