🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Holiday 7x7 Wargame - OAuth.py

News1 min read

OAuth vulnerabilities aren’t always obvious. Sometimes they hide in code that appears to work. In our Holiday 7×7 Wargame, we’ve crafted OAUTH.py, a challenge that does just that. It looks like a normal OAuth callback, but a subtle flaw allows clever players to bypass trust boundaries and gain unintended access.

Think you can fix it? Try it now, dive into the flow, and see if you can patch the vulnerability before moving on to the next challenge.

:backhand_index_pointing_right: Start OAUTH.py now: https://play.secdim.com/game/holiday-2025/challenge/oauthpy

Happy patching, and don’t forget each challenge is part of the Holiday 7×7 Wargame, designed to sharpen your skills over the break.

Questions or comments? Discuss this post on SecDim Community →

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing — fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.