$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: Flask+Vue app with admin bot, complaint system with unsanitized prediction field rendered via v-html, and authenticated model upload endpoint calling keras.models.load_model(). Solution: 3-step chain — stored XSS via img onerror in prediction field, use admin browser context to upload malicious .h5 model with Lambda layer containing os.system() RCE, exfiltrate flag via curl.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar