← ALL WRITEUPS

RESEARCHNODE / WRITEUP

aiscrimination dctf 2026 writeup

DefCamp D-CTF Aiscrimination writeup covering CSS injection, server-side @import processing, path traversal through resolved theme paths, and arbitrary file read to retrieve the flag.

webcss-injectionlfi

recon the app lets us create public cards and our statement gets inserted directly into generated css. i found css injection pretty fast and could inject my own @import, but honestly got stuck here for like 2 hours. i was trying to figure out how css injection could even help and didnt realize that @import wasnt handled by browser at all, it was being parsed server-side. after trying: "; } @import “/proc/self/cwd/app.py”; .identity-card::after { content:" the generated css actually contained app.py contents. thats when it finally clicked. exploit from app.py i found this: (THEME_ROOT / requested).resolve().read_text() it resolves …/ but never checks if final path is still inside THEME_ROOT, so basically arbitrary file read. then i just tried few useful paths through injected imports, including: /proc/self/cwd/…/flag.txt /home/ctf/flag.txt requested generated identity.css and checked it for flag,got: CTF{5bb9cb8b8ff43e243fe85fceaf646e7ba6a5c80250e96678be2aa71add38eb97}

END OF NOTE / dencent444MORE WRITEUPS ↗