Probably the most modern and sophisticated insecure web application
The Open Worldwide Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software. Through community-led open source software projects, hundreds of local chapters worldwide, tens of thousands of members, and leading educational and training conferences, the OWASP Foundation is the source for developers and technologists to secure the web.
Translating "dump" or "useless outfit" into German yields "Saftladen" which is a compound word from "Saft" and "Laden". This reverse-translates into "juice" and "shop". Hence the project name.
That the initials "JS" match with those of "JavaScript" was purely coincidental!
The most trustworthy online shop out there (@dschadow)
The best juice shop on the whole internet! (@shehackspurple)
Actually the most bug-free vulnerable application in existence! (@vanderaj)
First you 😂😂 then you 😢 (@kramse)
But this doesn't have anything to do with juice (@coderPatros' wife)
| Björn Kimminich | Jannik Hollenbach |
| 🏆WASPY Award 2021 "Outstanding Innovator" |
🏆WASPY Award 2025 "Project Person of the Year" |
Unsuspectingly browse the Juice Shop like Average Joe!
Covering various vulnerabilities and serious design flaws
OWASP Juice Shop covers all vulnerabilities from the latest OWASP Top 10 and more.
There's something to do for beginners and veterans alike
Challenge progress is tracked on server-side
Solved challenges are announced as push notifications
Identify the underlying code flaw and select an appropriate fix
Auto-saves your hacking progress and restores on server restart
The application cleanly reset on every startup and only restores challenge progress from a cookie.
All challenges come with one or more unlockable hints
Some challenges come with an embedded interactive tutorial
Complete all tutorials to unlock the entire Score Board
Solved challenges are rated based on cheating probability
Some challenges are disabled by default in Docker and on Heroku
This is the case for all Stored XSS (due to risk of site defacement), all XXE challenges (because they can lead to instance death by segfault error) and the SSTi, Deserialization and some NoSQLi challenges (as they could have unforeseeable side effects on the hosting platform). We do not recommend to carelessly turn safety mode off!
Official platform to run separate Juice Shop instances for training or CTF participants on a central Kubernetes cluster
Restricts number of users to team members and protects against illicit cross-team instance access
Trivial registration, transparent instance stickiness, CTF-friendly score board out-of-the-box, automatic light/dark mode
Projector-friendly, animated view of team scores for live events
Step-by-step guides for different platforms and cloud providers
The specifically designed LEGO tower allows bringing a 4x Raspberry Pi cluster with PoE & cooling fans to any training and have MultiJuicer instances running literally out of the box! Also needed: PoE switch, WiFi router, and Internet uplink via cable e.g. through additional WISP router. Build your own with our part list and build manual.
Utility to host a hacking event on CTFd, FBCTF or RootTheBox
Unless you really need a dedicated CTF server, we recommend using MultiJuicer instead of this extension. MultiJuicer provides an out-of-the-box solution for CTFs already with team-support, score board, live activity tracking, event timer and more.
FBCTF was discontinued in 2020, and RootTheBox last saw an update in 2024. We recommend CTFd if you really need a full-blown CTF server.
Locally via npm i -g juice-shop-ctf-cli or as Docker container
Run juice-shop-ctf on the command line and let a wizard create a data-dump to conveniently import into CTFd, FBCTF, or RootTheBox
Run juice-shop-ctf --config myconfig.yml to use non-interactive mode passing in configuration via YAML file
ctfFramework: CTFd | FBCTF | RootTheBox
juiceShopUrl: http://localhost:3000
ctfKey: https://raw.githubusercontent.com/bkimminich/juice-shop/master/ctf.key
countryMapping: https://raw.githubusercontent.com/juice-shop/juice-shop/master/config/fbctf.yml
insertHints: none | free | paid
Can be conveniently copy-pasted into the CTF score server
Your CTF score server instance will be ready-to-play in minutes
Fully customizable business context and look & feel
Customize the application via a simple YAML file
application:
domain: juice-sh.op
name: 'OWASP Juice Shop'
logo: JuiceShop_Logo.png
favicon: favicon_js.ico
theme: bluegrey-lightgreen
showVersionNumber: true
showGitHubLinks: true
numberOfRandomFakeUsers: 0
altcoinName: Juicycoin
privacyContactEmail: donotreply@owasp-juice.shop
customMetricsPrefix: juiceshop
social:
twitterUrl: 'https://twitter.com/owasp_juiceshop'
facebookUrl: 'https://www.facebook.com/owasp.juiceshop'
[...]
[...]
The YAML configuration allows you to override all products
products:
-
name: 'Product Name'
price: 100
description: 'Product Description'
image: '(https://somewhe.re/)image.png'
useForProductTamperingChallenge: false
useForChristmasChallenge: false
fileForRetrieveBlueprintChallenge: ~
reviews:
- { text: 'Customer review', author: jim }
-
name: 'Product with Lorem Ipsum description, filler image and random price'
Your config is validated on server startup to prevent broken or unsolvable challenges!
JavaScript/TypeScript all the way from UI to REST API
Comes with cloud, local and containerized run options
Crowd-sourced UI translations for 40+ languages
Maximizing Test Automation & Code Coverage
Automated Build, CI/CD & Code Analysis
Convenient monitoring, notification and data integration capabilities
Sends a payload to a specified URL whenever a challenge is solved
{
"solution": {
"challenge": "localXssChallenge",
"hintsAvailable": 2,
"hintsUnlocked": 0,
"cheatScore": 0,
"totalCheatScore": 0.15,
"issuedOn": "2025-09-04T18:24:33.027Z"
},
"ctfFlag": "b0d70dce...b85fac6785dba2349b",
"issuer": {
"hostName": "fv-az116-673",
"os": "Linux (5.4.0-1031-azure)",
"appName": "OWASP Juice Shop",
"config": "default",
"version": "19.0.0"
}
}
JSON template allows to import a dashboard into Grafana consuming and displaying all metrics gathered via Prometheus
Available free of charge as an online resource and via Leanpub
Some amazing facts & stats about the project
Visit our backlog on GitHub & translations on Crowdin
Issues labelled with good first issue and/or help wanted are the best starting point!
Creative masterpiece by singer-songwriter Brian Johnson (100% AI-free!)
Copyright (c) 2014-2026 Björn Kimminich / @bkimminich
Licensed under the MIT license.
Created with reveal.js - The HTML Presentation Framework
