Though, we notice in web requests, that there is a JWT cookie being sent over
So, at the end, we get the final sum for one of these cookies:
The specific request we have to look into is the GET /request
, which sends the cookie for the sum that it looks into.
Simply, resend the final sum, and we get the flag
TsukuCTF25{Tr4d1on4l_P4th_Trav3rs4l}