Simply watch the replay where flag is written with smoke.
Challenge refers to the famous osu! streamer, ThePooN. Flag is in his channel.
Either play the map and save osr, or edit osr file with online tools to fake the score.
Select all objects and we can clearly see all objects on the grid form a QRCode. Draw it or use some PS skills to get the code and scan it.
The vulnerability is aCropalypse in older Windows systems. Use online tool such as https://acropalypse.app/ and set resolution to 1920x1080 to recover the flag.