Remote Code Execution
The compute service passes your input straight to eval() inside
the Node.js server process. That means full runtime access: the filesystem,
the environment, and everything the process can read.
Objective
Weaponize an arithmetic evaluator into arbitrary code execution, then read the stage key from the server.
POST /api/computeaccepts{"expression": "…"}and returns the evaluated result.- The evaluation context is a real Node process — whatever the process can reach, your expressions can reach.
- The stage key lives on disk, somewhere the server process can read. Find it.
Execution sandbox
Live client for the compute endpoint. Expressions run on the server — be precise, not loud.
POST /api/compute
POST
Sanity checks
Response
Hints
Hint 1 — Confirm execution with something harmless
Start with
1+1 or process.version. If the server evaluates it, you have code execution — everything after is just enumeration.Hint 2 — eval means modules
require is in scope. Think about which built-in module lists directory contents — then start at '.' and see what the application keeps beside itself.Hint 3 — Hidden doesn't mean unreachable
A leading dot hides a directory from casual listings, not from enumeration. Once you find a module that exports secrets,
require() it directly — no need to read the file. And pay attention to what else is lying around: the Final Boss has its own notes on this disk.Claim the bounty
No submission form. No judging. The chain is the referee.
STEP 1
Execute & extract
Turn expression evaluation into filesystem access and pull the stage key from disk.
STEP 2
Import it
Load the base58 secret into any Solana wallet — Phantom, Solflare, or CLI.
STEP 3
Sweep the balance
Move the full 1 SOL to your own address. The scoreboard confirms on-chain.