miscmedium

Chrono Mind

HackTheBox

Task: abuse an AI-themed web service with room-scoped APIs, file-backed context loading, and a code-completion execution endpoint. Solution: chain path traversal into prompt injection to recover the copilot key, then use a minimal Python payload for reliable RCE and flag retrieval.

$ ls tags/ techniques/
path_traversal_exfiltrationprompt_injection_secret_extractionllm_generated_rcemulti_stage_api_chaining

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]