Thanks for putting this together. Was very educational working through each level (and felt great to capture the flag). Loved that it was spread out across node.js/python/ruby/php/javascript.
Were any unexpected security vulnerabilities found (or patched mid-game by you) in the overall infrastructure?
Not sure if this was intentionally left open-ended but for example in Level 6 I exploited a Ruby session/cookie bug to gain access to the target user, before realizing that the easier way was just a simpler JavaScript XSS vulnerability.