Exercises

Exercise Avg. Time Difficulty Solved by Tier
CVE-2026-XX130
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 1 PRO
CVE-2023-51XX9
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 1 PRO
CVE-2026-XX790
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 1 PRO
JWT: Refresh Token Bypass
This exercise covers bypassing JWT refresh token validation to maintain unauthorized access.
-- easy 0 PRO
CVE-2023-3X829
This challenge covers the review of a CVE in a Python codebase and its patch
-- hard 0 PRO
CVE-2026-21XX3
This challenge covers the review of a CVE in a Python codebase and its patch
-- hard 0 PRO
CVE-2026-2413X
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 0 PRO
CVE-2025-X9X28
This challenge covers the review of a CVE in a typescript codebase and its patch
-- hard 0 PRO
CVE-2025-X23XX
This challenge covers the review of a CVE in a javascript codebase and its patch
-- hard 0 PRO
CVE-2024-X170X
This challenge covers the review of a CVE in a JavaScript codebase and its patch
-- hard 0 PRO
CVE-2026-X189X
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 0 PRO
CVE-2025-625X8
This challenge covers the review of a CVE in a javascript codebase and its patch
-- hard 0 PRO
CVE-2025-XX953
This challenge covers the review of a CVE in a typescript codebase and its patch
-- hard 0 PRO
CVE-2026-XX871
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 0 PRO
CVE-2025-XX662
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 0 PRO
CVE-2026-XX951
This challenge covers the review of a CVE in a javascript codebase and its patch
-- hard 0 PRO
JWT: Signature Leak
This exercise covers exploiting a JWT signature leak to forge authentication tokens.
-- easy 0 PRO
CVE-2026-24895: FrankenPHP Path Confusion RCE using Unicode 1-2 Hr. hard 3 PRO
JWT: Invalid Algorithm
This exercise covers exploiting JWT algorithm validation flaws to bypass signature verification.
< 1 Hr. easy 11 PRO
CVE-2026-XX888
This challenge covers the review of a CVE in a typescript codebase and its patch
-- hard 0 PRO
CVE-2025-XX864
This challenge covers the review of a CVE in a typescript codebase and its patch
< 1 Hr. hard 49 PRO
CVE-2026-XX050
This challenge covers the review of a CVE in a typescript codebase and its patch
-- hard 0 PRO
CVE-2021-X27X0
This challenge covers the review of a CVE in a JavaScript codebase and its patch
-- hard 0 PRO
CVE-2020-XX079
This challenge covers the review of a CVE in a javascript codebase and its patch
-- hard 0 PRO
CVE-2021-437XX
This challenge covers the review of a CVE in a JavaScript codebase and its patch
-- hard 0 PRO
CVE-2026-XXX50
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 0 PRO
CVE-2025-XXX57
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 8 PRO
CVE-2024-XX3X9
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 0 PRO
CVE-2025-0X6X
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 40 PRO
CVE-2024-X68X
This challenge covers the review of a CVE in a python codebase and its patch
-- hard 35 PRO
1 2 3 4 24
Showing 1–30 of 699 exercises