<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SSRF on bokkapig</title><link>https://bokkapig.pages.dev/tags/ssrf/</link><description>Recent content in SSRF on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Sat, 01 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/ssrf/index.xml" rel="self" type="application/rss+xml"/><item><title>Cohort</title><link>https://bokkapig.pages.dev/writeups/cohort/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/cohort/</guid><description>An internal marimo notebook server — discovered by bypassing an SSRF host blocklist on the Cohort Analytics &amp;lsquo;source validator&amp;rsquo; — exposed the unauthenticated /terminal/ws endpoint (CVE-2026-39987), granting a pre-auth PTY as marimo. Privilege escalation abused a deliberately held-back PackageKit (CVE-2026-41651, &amp;lsquo;Pack2TheRoot&amp;rsquo;): a TOCTOU race in the D-Bus InstallFiles transaction let an unprivileged user install a malicious .deb whose postinst ran as root, dropping a SUID bash.</description></item></channel></rss>