The logic (implementation) contract does not disable its initializer in the constructor. This allows anyone to initialize it separately from the proxy, potentially taking control.
Unauthorized initialization can result in a malicious user setting themselves as principal
Manual review
Add this to the constructor of LevelOne.sol :
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.