<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Local Privilege Escalation on bokkapig</title><link>https://bokkapig.pages.dev/tags/local-privilege-escalation/</link><description>Recent content in Local Privilege Escalation on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Tue, 04 Aug 2026 14:45:21 +0100</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/local-privilege-escalation/index.xml" rel="self" type="application/rss+xml"/><item><title>Reactor</title><link>https://bokkapig.pages.dev/writeups/reactor/</link><pubDate>Tue, 04 Aug 2026 14:45:21 +0100</pubDate><guid>https://bokkapig.pages.dev/writeups/reactor/</guid><description>A ReactorWatch monitoring dashboard on port 3000 runs Next.js 15.0.3 with React 19.0.0 — vulnerable to React2Shell (CVE-2025-55182 / CVE-2025-66478), an unauthenticated RCE in the React Server Components Flight deserializer. A POST to / carrying a Next-Action header and a forged circular Flight chunk reaches Function via $1:constructor:constructor, giving code execution as the node service account. The app&amp;rsquo;s world-readable SQLite database yields engineer&amp;rsquo;s MD5 password hash, reused verbatim for SSH. Root comes from a root-owned uptime-monitor systemd unit launched with &amp;ndash;inspect=127.0.0.1:9229: the Node debug port is an unauthenticated root eval primitive, driven over the Chrome DevTools Protocol.</description></item><item><title>Cohort</title><link>https://bokkapig.pages.dev/writeups/cohort/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/cohort/</guid><description>An internal marimo notebook server — discovered by bypassing an SSRF host blocklist on the Cohort Analytics &amp;lsquo;source validator&amp;rsquo; — exposed the unauthenticated /terminal/ws endpoint (CVE-2026-39987), granting a pre-auth PTY as marimo. Privilege escalation abused a deliberately held-back PackageKit (CVE-2026-41651, &amp;lsquo;Pack2TheRoot&amp;rsquo;): a TOCTOU race in the D-Bus InstallFiles transaction let an unprivileged user install a malicious .deb whose postinst ran as root, dropping a SUID bash.</description></item><item><title>Silentium</title><link>https://bokkapig.pages.dev/writeups/silentium/</link><pubDate>Sat, 11 Apr 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/silentium/</guid><description>A staging Flowise 3.0.5 instance leaks a live password-reset token straight back in the /api/v1/account/forgot-password response (CVE-2025-58434), giving instant takeover of the &lt;a href="mailto:ben@silentium.htb"&gt;ben@silentium.htb&lt;/a&gt; admin account. Authenticated, the Custom MCP node&amp;rsquo;s mcpServerConfig (CVE-2025-59528) spawns arbitrary processes, yielding root inside the Flowise container — whose environment block hands over SMTP_PASSWORD, reused verbatim as ben&amp;rsquo;s system password over SSH. Root comes from a second internal app: Gogs 0.13.3 running as root with open registration, where CVE-2025-8110 lets the contents API write through a committed symlink to overwrite the repository&amp;rsquo;s pre-receive hook, executed as root on the next push.</description></item></channel></rss>