Daily & weekly challenges
Climb the leaderboards and earn achievements. Daily labs drill the fundamentals; weekly labs are built from real-world vulnerabilities you'd actually meet in a bug bounty program.
Hands-on web security training
Every Bugforge lab is a working application with a genuine bug in it — modelled on vulnerabilities people actually report. A fresh one lands every day, in your browser, with nothing to install.
New lab every 24h · Runs in the browser · Free to start
What you get
Everything runs in the browser against a real, running application — not a quiz, not a video course.
Climb the leaderboards and earn achievements. Daily labs drill the fundamentals; weekly labs are built from real-world vulnerabilities you'd actually meet in a bug bounty program.
Ordered courses that take one technique from "what even is this" to hunting it in the wild — methodology, filter bypasses, real CVEs. Every module ends in a lab, so you prove it rather than read it.
The same labs make a clean, repeatable benchmark for an autonomous agent. Point your scanner or LLM at them, see exactly where it stalls, and measure the fix.
Solutions open up once you've solved — or once the clock runs out. Read how other people got there, post your own write-up, and ask when you're stuck.
Deep dive · now live
Client-Side Path Traversal is the first Bugforge deep dive: how CSPT lets you steer a browser's own requests, how to hunt it in a real application, and how a "low impact" finding chains into request forgery, XSS and account takeover.
Written for pentesters, bug bounty hunters and AppSec engineers who already know their way around HTTP — and every module ends in a lab.
Open the CSPT deep diveModule 01
Module 02
Free to start
Create an account, open the lab, and see how far you get. If you get stuck, the write-ups are right there.
Create your free account