Download Latest Version juice-shop-18.0.0_node22_darwin_x64.zip (164.8 MB)
Email in envelope

Get an email when there's a new version of OWASP Juice Shop

Home / v17.2.0
Name Modified Size InfoDownloads / Week
Parent folder
juice-shop-17.2.0_node18_linux_x64.tgz.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node18_darwin_x64.zip.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node18_linux_x64.tgz 2025-03-14 133.5 MB
juice-shop-17.2.0_node18_darwin_x64.zip 2025-03-14 175.0 MB
juice-shop-17.2.0_node20_darwin_x64.zip.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node18_win32_x64.zip.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node20_darwin_x64.zip 2025-03-14 175.0 MB
juice-shop-17.2.0_node18_win32_x64.zip 2025-03-14 201.8 MB
juice-shop-17.2.0_node21_linux_x64.tgz.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node20_linux_x64.tgz.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node21_linux_x64.tgz 2025-03-14 133.8 MB
juice-shop-17.2.0_node20_linux_x64.tgz 2025-03-14 133.5 MB
juice-shop-17.2.0_node22_linux_x64.tgz.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node22_linux_x64.tgz 2025-03-14 133.8 MB
juice-shop-17.2.0_node22_darwin_x64.zip.md5 2025-03-14 32 Bytes
juice-shop-17.2.0_node22_darwin_x64.zip 2025-03-14 175.2 MB
README.md 2025-03-14 1.3 kB
v17.2.0 source code.tar.gz 2025-03-14 48.7 MB
v17.2.0 source code.zip 2025-03-14 49.3 MB
Totals: 19 Items   1.4 GB 2

This release brings significant changes to existing challenges (⚡) which might break canned CTF setups as well as solution guides made for previous versions of OWASP Juice Shop!

🅰️ Frontend

  • Updated frontend to Angular 17.x and Angular Material 17.x (kudos to @martinakraus, @thomasbreland, @hxrshxz, @ayushrajparihar and @alekszivko for the help and hard work on this 🙌)

🎯 Challenges

🔧 Configuration

  • Added blueSkyUrl and mastodonUrl to social section of configuration

🎨 User Interface

  • Added BlueSky and Mastodon links to About Us screen

🐛 Bugfixes

  • [#2341]: Fixed "Product Tampering" challenge verification to work in any selected language
  • [#2365]: Restored prevention of unintentional RCE in NoSQL challenges (kudos to @KapilSareen)
  • [#2384]: Now checking challenge continue code for invalid characters before processing (kudos to @drwtsn95)
  • [#2404]: Fixed "Upload Size" challenge verification to trigger properly in all situations (kudos to @criticic)
  • [#2317]: Hacking Instructor script is now again lazy-loaded into the browser (kudos to @alekszivko)
Source: README.md, updated 2025-03-14