DevHub-HackTheBox-ss11

SuriyaBoon
1
HTB Season 11 — DevHub Writeup Exploiting CVE-2026-23744 (MCPJam Inspector unauthenticated RCE via /api/mcp/connect) to gain initial foothold, then lateral movement through Jupyter Lab token leaked in systemd service file. Stack: nginx · MCPJam Inspector 1.4.2 · Jupyter Lab · OPSMCP (root)

Content