
CodeTwo from @hackthebox_eu features a js2py sandbox escape via CVE-2024-28397, MD5 hash cracking from SQLite, and abusing npbackup-cli sudo permissions to read root's SSH key from backups. https://0xdf.gitlab.io/2026/01/31/htb-codetwo.html
Post summary
The blog post details an exploit of CodeTwo via CVE-2024-28397, highlighting a js2py sandbox escape and additional vulnerabilities such as MD5 cracking and privilege abuse to read root SSH keys.


