grep -l "PHP-Injection" ./machines (2)

Kobold [Linux]
Easy
MCP Inspector STDIO RCE for foothold, PHP code injection in PrivateBin container to leak credentials, Docker escape via Arcane container management.
MCPDockerPrivateBinPHP-injectionpassword-reuseArcane
โ— pwned
VariaType [Linux]
Medium
Exploited fonttools CVE-2025-66034 designspace path traversal to write a PHP webshell, escalated to user via FontForge archive command injection, then root via setuptools PackageIndex arbitrary file write to cron.d.
fonttoolsCVE-2025-66034path-traversalPHP-injectionLFIgit-exposure +5
โ— pwned