Hands-on web security training

The most realistic web security labs.

Every Bugforge lab is a working application with a genuine bug in it — modelled on vulnerabilities people actually report. A fresh one lands every day, in your browser, with nothing to install.

New lab every 24h · Runs in the browser · Free to start

Daily lab
Fundamentals, ~20 minutes
Weekly lab
Modelled on a real-world vulnerability
Deep dive
One technique, taken all the way down

What you get

Four ways to get sharper at finding bugs.

Everything runs in the browser against a real, running application — not a quiz, not a video course.

Daily & weekly challenges

Climb the leaderboards and earn achievements. Daily labs drill the fundamentals; weekly labs are built from real-world vulnerabilities you'd actually meet in a bug bounty program.

  • Leaderboards
  • Achievements
  • Streaks

Learning paths that go deeper

Ordered courses that take one technique from "what even is this" to hunting it in the wild — methodology, filter bypasses, real CVEs. Every module ends in a lab, so you prove it rather than read it.

  • Guided
  • Lab-backed
  • Self-paced

Learn to hack — or tune your AI

The same labs make a clean, repeatable benchmark for an autonomous agent. Point your scanner or LLM at them, see exactly where it stalls, and measure the fix.

  • Agent benchmarks
  • Repeatable
  • Scored

A community that explains itself

Solutions open up once you've solved — or once the clock runs out. Read how other people got there, post your own write-up, and ask when you're stuck.

  • Write-ups
  • Hints
  • Discussion

Deep dive · now live

Take one technique all the way down.

Client-Side Path Traversal is the first Bugforge deep dive: how CSPT lets you steer a browser's own requests, how to hunt it in a real application, and how a "low impact" finding chains into request forgery, XSS and account takeover.

Written for pentesters, bug bounty hunters and AppSec engineers who already know their way around HTTP — and every module ends in a lab.

Open the CSPT deep dive

Module 01

What CSPT actually is

  • Looking at some code
  • What the reports show
  • CVEs, frameworks and bounties
  • Limits and defences
  • Lab: your first CSPT

Module 02

How to hunt CSPT

  • The hunting methodology
  • Encoding and normalisation quirks
  • Getting past filters, WAFs and validators
  • Turning "low impact" into real damage
  • Labs: prove it, then go hunt

Free to start

Today's lab is already waiting.

Create an account, open the lab, and see how far you get. If you get stuck, the write-ups are right there.

Create your free account