Writeups/TryHackMe/Love At First Breach CTF 2026

Love At First Breach CTF 2026

A beginner friendly, live red-teaming CTF designed to help you fall in love with breaking things... safely.

View event on TryHackMe

//Rooms

Valenfind

Medium

Step-by-step Valenfind TryHackMe writeup from Love At First Breach CTF 2026: LFI path traversal, Flask app source leak, and admin API key leading to the flag.

→

Hidden Deep Into my Heart

Easy

Hidden Deep Into my Heart TryHackMe writeup — Love At First Breach 2026: robots.txt disclosure, directory fuzzing, and default credentials to Cupid's secret vault flag.

→

Signed Messages

Medium

Signed Messages TryHackMe writeup — Love At First Breach 2026: LoveNote deterministic RSA, /debug key leak, and PSS signature forgery to capture the flag.

→

Corp Website

Medium

Corp Website TryHackMe writeup — Love At First Breach 2026: CVE-2025-55182 React2Shell unauthenticated RCE, Dockerfile leak, and sudo python3 privilege escalation.

→

CupidBot

Easy

CupidBot TryHackMe writeup — Love At First Breach 2026: prompt injection, system prompt leakage, and role impersonation to capture all three flags.

→

TryHeartMe

Easy

TryHeartMe TryHackMe writeup — Love At First Breach 2026: JWT decode, role tampering without re-signing, and access to hidden ValenFlag for the flag.

→

Speed Chatting

Easy

Speed Chatting TryHackMe writeup — Love At First Breach 2026: profile picture upload, Python reverse shell, and root RCE to capture the flag.

→

Cupid's Matchmaker

Easy

Cupid's Matchmaker TryHackMe writeup — Love At First Breach 2026: stored XSS in survey, admin bot review, and exfiltration of /flag to capture the flag.

→

Love Letter Locker

Easy

Love Letter Locker TryHackMe writeup — Love At First Breach 2026: predictable letter IDs and missing ownership check leading to IDOR and flag.

→

When Hearts Collide

Medium

When Hearts Collide TryHackMe writeup — Love At First Breach 2026: MD5 match logic flaw, generic collision with fastcoll, and flag from duplicate-hash match.

→

$ echo "Open to Red Team Security Research and Security Engineering roles."

> Open to Red Team Security Research and Security Engineering roles.

$ uptime

> Portfolio online since 2024 | Last updated: Mar 2026

"No one is useless in this world who lightens the burdens of another." — Charles Dickens

Considered a small donation if you found any of the walkthrough or blog posts helpful. Much appreciate :)

Buy me a coffee

© 2026 Shivang Tiwari. Built with Next.js. Hack the planet.