creator Intigriti's January challenge

Find the FLAG and win Intigriti swag! 🏆

Rules:
  • This challenge runs from 20/01/2026 12:00 PM until 27/01/2026, 11:59 PM UTC.
  • Out of all correct submissions, we will draw six winners on Wednesday 28/01/2026:
    • Three randomly drawn correct submissions
    • Three best write-ups
  • Every winner gets a €50 swag voucher for our swag shop
  • The winners will be announced on our Twitter profile.
  • For every 100 likes, we'll add a tip to announcement tweet.
  • Join our Discord to discuss the challenge!
The solution:
  • Should leverage a XSS vulnerability on the challenge page.
  • Shouldn't be self-XSS or related to MiTM attacks.
  • Should work in the latest version of Google Chrome.
  • Should not require more than 1 click from the victim.
  • Should include:
    • The flag in the format INTIGRITI{.*}
    • The payload(s) used
    • Steps to solve (short description / bullet points)
  • Should be reported on the Intigriti platform.
Get started:
  1. Test your payloads on the challenge page
  2. Submit your proof of concept on the submission page to capture your flag!