NodeBazaar, the 2026 rewrite of vulnerable-node: a working Node.js shop on PostgreSQL and MongoDB with real vulnerable code paths mapped to the OWASP Top 10:2025, including IDOR, SSRF to a mock cloud metadata service and vault, SQL and NoSQL injection, mass assignment, stored XSS, forgeable JWTs and prototype pollution.
Not startedDockercommit fb33dabx86_64 · aarch64Secret
Exploit the shop's vulnerabilities, from the order IDOR to the SSRF that reaches the vault secret.
The brief for this lab lives in its repository.