← All Labs
🛡 SSRF INTERMEDIATE +90 XP · +40 no-hint bonus

SSRF — Image URL Fetcher

AvatarFetcher takes a URL and downloads the image server-side. The fetcher has no allowlist — point it at an internal-only address to read cloud metadata.

https://bookshop.local/search