Tags: ssti 

Rating:

so to ommit blacklist on convencional python words I have used http GET params and now used SSTI as always, flag was printed in flag.txt file in working directory

Original writeup (https://github.com/eroloo/ctf/tree/main/ImaginaryCTF/Build-a-website).