An intentionally vulnerable restaurant API built with FastAPI and PostgreSQL. Starting as a low-privileged API user, chain API flaws such as broken authorization, weak JWT handling and injection to reach root on the server.
Not startedDockercommit 0a63abbx86_64 · aarch64Secret
Escalate from a low-privileged API user to root on the server.
The brief for this lab lives in its repository.