Published onJuly 20, 2026AthenaCTF 2026 - Session SlipwebWebwebAthenaCTFAthenaCTF-2026NameBarryPLThe challenge involved finding a source leak via express.static, bypassing authentication via the dbg. session prefix and exploiting path traversal in /export.