Screenshot 2025-12-18 at 18.53.10.png

1. Challenge Information

2. TL;DR Solution Summary

The endpoint improperly validated JWTs, allowing us to forge a token by modifying the algorithm field to "none", granting admin access.

3. Recon / Initial Analysis

3.1 Files/ Informations Provided

3EPrcBh52dtr4XdJB8tdZvLVzVYiSJ.zip

4. Vulnerability Breakdown

Keep this section conceptual and readable.

5. Exploitation

Step-by-step explanation of how you solved it.