Narnes and Bobles & Bobles and Narnes LA CTF 2026 Bun Type-Confusion Javascript Sqlite Web Two type confusion bugs in a Bun bookstore: string price NaN trick, then batch INSERT column inference.
Blogler LA CTF 2026 Yaml Path-Traversal Aliasing Lfi Web YAML anchor aliasing creates a shared reference that bypasses path validation via display_name mutation.
Zazastore PascalCTF 2026 Javascript Type-Confusion NaN Web NaN comparison bypass in a Node.js shopping cart.
Travel Playlist PascalCTF 2026 Path-Traversal Lfi Web Path traversal via unsanitized file path parameter.
Pdfile PascalCTF 2026 Xxe Xml Blacklist-Bypass Web XXE injection with blacklist bypass via URL encoding.