About - OopsSec Store
Security training for the apps you actually ship.
OopsSec Store is an open-source, deliberately vulnerable e-commerce app built on Next.js, React, TypeScript and Prisma. It holds 36 challenges across web, API, authentication, business logic, cryptography, supply chain, AI agents and MCP. Find the bugs, exploit them, and understand why they work.
This site hosts the walkthroughs: one per challenge, from vulnerability to exploit to fix.
Quick start
# With Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
# With Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store
Then open http://localhost:3000 and start hacking.
Getting started
- Start the lab with one of the commands above. The store comes up on
localhost:3000. - Go after challenge #1, the public env variable leak: a payment secret that Next.js bakes into the client bundle. Easy, 15–20 minutes, nothing but your browser devtools.
- Stuck? Read the walkthrough. The first one is Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js.
- Validate the flag. Paste
OSS{...}into the flag checker, the floating widget on every page. Your player dashboard tracks what is left. - Pick the next one. The roadmap orders every challenge across chapters, with difficulty, time estimate and prerequisites.
New to offensive security? The TryHackMe room, The Summer Audit, wraps the first flags in a guided narrative across 8 tasks and 7 flags.
Why OopsSec Store?
Modern frameworks change where security vulnerabilities appear and how they should be fixed. OopsSec Store puts the classic vulnerability classes (XSS, CSRF, IDOR, JWT attacks, path traversal, SQL injection and more) into a stack many developers use today.
Server-rendered components, middleware and ORMs introduce different trust boundaries and failure modes. Several challenges also reproduce published CVEs against this stack.
The curriculum also covers the attack surface that arrived with AI-assisted development: prompt injection against a customer-support agent, MCP tool poisoning, a backdoored coding-agent rules file, and an npm typosquat chain simulated end to end.
Features
- 36 CTF challenges across 11 chapters, laid out as a structured learning roadmap
- A walkthrough and an in-app vulnerability reference for each challenge
- A player dashboard tracking progress by difficulty and category
- A Hall of Fame for players who capture every flag, with a shareable badge
- Automated tests that verify exploits still work: a PR that accidentally fixes a vulnerability fails CI
Resources
- GitHub Repository
- npm Package
- Docker Image
- OWASP Vulnerable Web Applications Directory
- TryHackMe room: The Summer Audit
- Educator Kit: OWASP coverage grids, syllabus templates, deployment FAQ
- Challenge feed (JSON): the curriculum in machine-readable form
- Discussions: questions, solves and challenge ideas
Disclaimer
OopsSec Store is for educational and authorized security testing only. It contains intentional vulnerabilities and insecure configurations, and must never be deployed in a production environment. Use it in isolated environments.
Contributing
OSS – OopsSec Store is MIT-licensed. Contributions are welcome: new challenges, walkthroughs, app extensions, bug fixes and documentation.
Grab a good first issue, or read the Contributing Guide. For bugs in the lab itself, open a GitHub Issue.