SmartHire from HackTheBox features an MLflow instance with creds from the docs, pickle deserialization in a PyFunc model for RCE, and a Python path configuration file dropped into a writable plugin directory for root.
0xdf.gitlab.io
HTB: SmartHire
SmartHire is a Linux box hosting an AI-powered HR site that trains AI models to score resumes. I’ll find an MLflow instance on a subdomain behind HTTP basic auth, and get in with example credentials from the MLflow documentation. From there I’ll abuse a deserialization vulnerability in how MLflow loads PyFunc models, overwriting the pickled model over the artifacts API so that my code runs the next time the site scores a resume, giving a shell. To escalate, I’ll find a script that runs with sudo and adds a writable directory to the Python path. I’ll craft a malicious path configuration file, which Python executes as code when the script starts.