Metalens Pro
Challenge
A photo service that processes uploads with ExifTool. The version is old enough to be the point.
Solution
The processing path is vulnerable to CVE-2021-22204, an ExifTool flaw where a crafted DjVu file with a malicious metadata field gets evaluated and runs code. Build the malicious image with the public proof of concept, upload it, and the embedded command runs on the server.
Flag
MetaCTF{exif_to0l_versi0n_c4n_kill_you}