$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: a Flask hiring portal used an authenticated ML workflow backed by a hidden MLflow instance with default credentials and unsafe model loading. Solution: poison python_model.pkl through the MLflow artifact API to get code execution as svcweb, then abuse a sudo-run Python tool that loads writable plugin paths with site.addsitedir() to execute a .pth payload as root.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar