A research shortlist of publicly documented Web CTF challenges with zero, one, or two recorded human solves. Counts are event-time snapshots, not proof of quality, fairness, or current reproducibility.
Checked 10 September 2026. Scope: difficult Web and browser-adjacent challenges for reference and candidate-primitive research.
Shortlist
| Challenge | Event | Solves | Technique | Research status |
|---|---|---|---|---|
| Slay the Note | SECCON CTF 14 Finals, 2026 | 0/18 | Cookie parsing | Source and solver published; no contestant solve |
| Shadow CSS | SECCON CTF 14 Finals, 2026 | 1/18 | Firefox, Link/CSS behavior | Source and solver published |
| impossible-leak | SECCON CTF 14 Quals, 2025 | 1 | Cross-site ETag length oracle | Source published; recorded solve was unintended |
| Captivating Canvas Contraption | SEKAI CTF 2025 | 1 | WebAssembly–JavaScript prototype traversal and CSP escape | Player writeup and exploit available |
| pure-leak | ASIS CTF Quals 2025 | 2 | Quirks mode, PHP warnings, networkless CSS exfiltration | Source published |
| W4 Schools | ASIS CTF Finals 2025 | 2 | CSP frame-ancestors oracle | Source and solver available |
| See in the Dark | SCC 2024 Quals | 2 | Cookie-parser confusion exposing an HttpOnly cookie | Source available; first solve after 13h29m |
| hidden-note | SECCON CTF 2023 Quals | 1 | XS-Leak using shared notes and Go unstable sorting | Public writeup and event archive |
| Sharer's World | HITCON CTF 2023 | 1 | Signed Exchange, certificate recovery, LFI and bot navigation | Source-assisted; infrastructure-heavy |
| chess.rs | DiceCTF 2023 | 2 | Rust/WASM memory corruption leading to browser XSS | Source and player writeup available |
| ptMD | m0leCon 2022 | 1 | React/Puppeteer navigation behavior, CSP and browser timing | Author source and writeup available |
| Disco Festival | zer0pts CTF 2022 | 1 | Advanced browser/Web exploitation chain | Official author writeup and public repository |
| Zer0TP | zer0pts CTF 2022 | 1 | Web/misc compression-oracle chain | Official author writeup and public repository |
| Beginner's Web 2021 | TSG CTF 2021 | 1 | JavaScript thenable-object state corruption | Source-assisted writeup |
| Watchers | Pwn2Win CTF 2020 | 2 | Wappalyzer ReDoS combined with XSS | Source published; old dependencies |
| Where Is My Cash | ALLES! CTF 2020 | 2 | Browser cache leak, XSS, SSRF and SQL injection | Official and alternate writeups available |
Highest-priority research targets
- impossible-leak — recent, source-available browser primitive; the only event solve used an unintended route.
- Slay the Note / Shadow CSS — newest zero/one-solve references with public source and solver material.
- Captivating Canvas Contraption — rare WebAssembly/JavaScript boundary behavior with a documented one-solve path.
- pure-leak — recent browser parsing and CSS exfiltration chain with only two solves.
- See in the Dark — substantial blog and admin-bot workflow; two solves and a 13h29m first solve.
Evaluation cautions
- Low human solve count does not prove that a challenge is fair, functional, or AI-resistant. Zero solves can indicate an implementation defect or a guessing gap.
- These public writeups may be present in model training or retrieval corpora. They are reference material, not clean AI-benchmark candidates.
- Browser-dependent challenges must be reproduced on the exact intended browser and version. Older Firefox, Chromium, Puppeteer, Wappalyzer and Signed Exchange behavior may have drifted.
- Do not copy an existing challenge or automatically promote its application concept. Any use here still requires author approval.
- Before combining vulnerabilities, isolate each approved primitive in a player-equivalent candidate, validate the complete reference solve and grader controls, run
simple-playtest, and record a fresh clean-room AI solve route and time. Repeat every gate after assembly.