Otto the otter, courier

Document Retrieval

Otto's Shortcut

Ask Otto for a delivery receipt by name and he'll fetch it from the archive without a second thought. He's fast, he's reliable, and he has never once questioned whether a filename is trying to sneak somewhere it shouldn't.

Otto's archive holds delivery receipts only — or so he says. Why would he double-check? Everyone who asks is clearly just looking for their receipt.

Find the flag, in the format SPAM{this_is_an_example}. This container resets every 24 hours.


Pick a document, or type a name of your own.

What's the vulnerability?

  • Path traversal (directory traversal) happens when an app builds a file path from user input without checking that the result stays inside the folder it's meant for.
  • Sequences like ../ walk back up the directory tree to files the app never intended to expose.
  • Node's path.join() is often assumed to sanitize paths — it doesn't. It just joins segments, and ../ still does its job.

Why does it matter?

Any file the running process can read becomes fair game: configuration files, credentials, source code, or anything else sitting outside the "safe" folder.

How to fix it

Resolve the final path and verify it still starts with the intended base directory before reading anything. Reject names containing .. or path separators, and prefer an allow-list of known document IDs over caller-supplied filenames.