<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Token Leak on bokkapig</title><link>https://bokkapig.pages.dev/tags/token-leak/</link><description>Recent content in Token Leak on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Sat, 30 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/token-leak/index.xml" rel="self" type="application/rss+xml"/><item><title>DevHub</title><link>https://bokkapig.pages.dev/writeups/devhub/</link><pubDate>Sat, 30 May 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/devhub/</guid><description>DevHub exposes an MCPJam Inspector v1.4.2 on 6274 bound to 0.0.0.0; its unauthenticated /api/mcp/connect endpoint passes serverConfig.command and serverConfig.args straight to the Node spawner (CVE-2026-23744, CVSS 9.8), giving a reverse shell as mcp-dev. A JupyterLab server on 127.0.0.1:8888 leaks its &amp;ndash;ServerApp.token on the process command line, so tunnelling 8888 and pasting the token yields an IPython console running as analyst and the user flag. Root comes from an internal Flask &amp;lsquo;OPSMCP&amp;rsquo; service on 127.0.0.1:5000 whose world-readable /opt/opsmcp/server.py hardcodes its X-API-Key and registers an undocumented ops._admin_dump tool that cats /root/.ssh/id_rsa — the returned key logs straight in as root.</description></item></channel></rss>