Intigriti · July 2026 · Web Challenge

Canonically Yours

Signing one package, publishing another — a JSON duplicate-key parser differential that quietly breaks a per-namespace authorization boundary and reads a protected report.

manifest.json — one byte-string, two readings
{
1"package": { "scope": "@me",   "name": "hello-world" },
2"package": { "scope": "core", "name": "security-notes" },
  "operation": "preflight"
}
1 Authorizer
POST /api/manifests/sign

reads the first package → scope == my namespace → authorized

2 Generator
POST /api/publications

reads the last package → renders @core/security-notes → the flag

Challenge
challenge-0726.intigriti.io
Author
zerodaysbooks (@silent_web3_)
Researcher
rajib_mahmud (Intigriti)
Bug class
Duplicate-key parser differential → authz bypass
CWE
436 · 285 · 639
Impact
Cross-namespace confidentiality break
Interaction
None · any self-service account
Intigriti Web Parser Differential Authorization Solved
Flag captured INTIGRITI{019f8700-4613-74fb-923e-781903e4bee9}