Cohort - HTB Machine Writeup
Difficulty: Easy | OS: Linux | Status: Completed
Chain an SSRF loopback bypass to Marimo's unauthenticated WebSocket RCE (CVE-2026-39987), then pop root with the PackageKit TOCTOU race (CVE-2026-41651).
Tags: SSRF, CVE-2026-39987, CVE-2026-41651
[ LOADING MACHINE DATA... ]
_