grep -l "Bash Arithmetic Evaluation" ./machines (1)

Browsed [Linux]
Medium
Malicious Chrome MV3 extension uploaded to server-side browser achieved RCE via bash arithmetic evaluation in a Flask/bash backend, then escalated to root via .pyc injection into a world-writable __pycache__ directory of a sudo-allowed Python script.
Chrome extensionbash arithmetic evaluationPython pyc injectionsudo abuseGiteaFlask
● pwned