Escaping a parenthesis-, quote-, and digit-free Python eval jail using a comprehension setattr as a call primitive and object.__reduce__ to reach the real builtins
Sidestepping a capstone control-flow jailer by handing native-compile a filename instead of a lambda, so the byte compiler reads flag.txt as Lisp and names it in an undefined-variable warning
Steering a byte-CNN malware classifier to a benign verdict with an adversarial comment, then escaping a Java SecurityManager through the trusted MethodHandles lookup
Declaring an axiom to fabricate false proofs, turning Lean 4 proof-carrying array accessors into arbitrary memory reads, and forging a closure object to call readFile
When softplus weights make every added byte incriminating, rewriting a Java SecurityManager escape token by token until a byte-CNN calls it benign
Writeup for Chusembly from EHAX CTF 2026. A miscellanious challenge involving sandbox escape and arbitrary Python code execution via an unrestricted custom assembly interpreter.