RESEARCHNODE / WRITEUP
aiscrimination dctf 2026 writeup
DefCamp D-CTF Aiscrimination writeup covering CSS injection, server-side @import processing, path traversal through resolved theme paths, and arbitrary file read to retrieve the flag.
recon the app lets us create public cards and our statement gets inserted directly into generated css. i found css injection pretty fast and could inject my own @import, but honestly got stuck here for like 2 hours. i was trying to figure out how css injection could even help and didnt realize that @import wasnt handled by browser at all, it was being parsed server-side. after trying: "; } @import “/proc/self/cwd/app.py”; .identity-card::after { content:" the generated css actually contained app.py contents. thats when it finally clicked. exploit from app.py i found this: (THEME_ROOT / requested).resolve().read_text() it resolves …/ but never checks if final path is still inside THEME_ROOT, so basically arbitrary file read. then i just tried few useful paths through injected imports, including: /proc/self/cwd/…/flag.txt /home/ctf/flag.txt requested generated identity.css and checked it for flag,got: CTF{5bb9cb8b8ff43e243fe85fceaf646e7ba6a5c80250e96678be2aa71add38eb97}