Writeups from Day 2 of SRCTF 2026, held on 16/08/2026
Challenges
- This Seems Odd - IDOR in the patient roster exposes a hidden high-value patient
- I See You - the record endpoint’s base64 ref lets you read the high-value patient’s record PDF
- I’ll Be Reading That - XXE in the eRx prescription import leaks the .env with the Flask session signing key
- The Auditor - GraphQL alias ordering bypass leaks the diagnostic token, unlocking command injection on the worker
