WebVerse
WebVerse
webverselabs.com

Labs

Every lab is a full stack. You’re not solving riddles — you’re chaining real bugs.

Arcadenal cover
Medium
Arcadenal

A retro arcade startup bolted "approval tokens" onto their onboarding flow...

Aster Check cover
Master
Aster Check

Signed-URL fetch gateway with legacy v1 signing oracle, internal ops console SQLi, restricted SSTI env leak, and a canary code host that leaks the signing key in git history.

HarborLedger cover
Medium
HarborLedger

Sourcemap leak reveals a legacy ops bridge and hidden fixtures.

Leak Lore cover
Hard
Leak Lore

Chain: Unauthenticated order-tracking BOLA leaks customer creds -> discover hidden /login on store -> login posts to auth-user API -> invoice downloader URL pivot to auth-admin…

LinkLapse cover
Medium
LinkLapse

LinkLapse ops suite. Exploit an OAuth account-linking flaw to bind your LinkID identity to a support seat (ATO).

OrbitDesk cover
Hard
OrbitDesk

Password reset token forgery -> GraphQL object authorization bug -> documents key leak -> signed link path traversal -> JWT forgery -> SSRF into internal ops -> diagnostics comm…

Pixel Pivot cover
Hard
Pixel Pivot

Chain: SQLi auth foothold -> SQLi dump weak QA hash -> reuse creds to internal chat -> obtain Gitea creds -> leak internal API key from old commit -> command injection on intern…

Poppet cover
Master
Poppet

Poppet is a boutique toy studio with interconnected services handling storefront, fulfillment, CRM, and payroll.

Quarter Shift cover
Hard
Quarter Shift

Quarter Shift is a multi-subdomain casino web app with tournaments, SSO, and an internal backoffice.

ReelHouse cover
Hard
ReelHouse

An independent cinema chain discovers irregularities in its internal management platform.

Role Riptide cover
Easy
Role Riptide

Accounting PM portal with a mass-assignment role escalation that unlocks classified client projects.

Switchback cover
Medium
Switchback

A partner-facing referral API ships with public docs that expose a demo webmail login.

Tenant Tilt cover
Easy
Tenant Tilt

Multi-tenant billing portal with a broken object-level authorization check in invoice retrieval.

Token Tomb cover
Easy
Token Tomb

PulsePay console uses JWTs but accepts alg=none, allowing role escalation to admin and exposure of foreign partner PII.

Tricky Tunnels cover
Easy
Tricky Tunnels

Unauthenticated debug endpoint leaks sensitive config (classic info disclosure).

Zipline cover
Medium
Zipline

Law firm case exports. Downloading exports by public ID leaks an internal subdomain and credentials, leading to a second API with hidden config.

Labs — WebVerse