
HTB: Nexus
Two independent leaks combine to log into a CRM as the wrong-but-reused password, an authenticated file-upload CVE gets a shell, and a custom root-owned systemd timer with unsanitised git plumbing is abused via a hand-crafted malicious tree object to plant an SSH key as root.
- #credential-access
- #file-upload
- #privesc
- #git-internals


